Impact
The WordPress Movie Booking plugin (Ovatheme) contains a path traversal flaw (CWE‑22) that allows an attacker to delete arbitrary files within the WordPress installation. The deletion can affect configuration files, themes, or other assets, potentially disrupting site operation. The vulnerability arises because the plugin does not properly constrain user‑supplied file paths, enabling path traversal.
Affected Systems
All releases of the Ovatheme Movie Booking plugin through version 1.1.5 (and earlier) are affected. The plugin is deployed on WordPress sites where administrators or developers install it.
Risk and Exploitability
With a CVSS score of 8.6, the vulnerability is considered high severity. The EPSS score of less than 1 % indicates that observed exploitation is rare, and it is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could supply a crafted file path through the plugin’s interface or an exposed endpoint to force deletion of arbitrary files. No authentication or elevated privileges are mentioned, so the flaw may be exploitable by unauthenticated or low‑privilege users. The risk factors therefore combine a severe impact with a low probability of exploitation at present.
OpenCVE Enrichment