Impact
Improper limitation of a pathname allows an attacker to craft a path that bypasses the intended restricted directory, enabling deletion of arbitrary files on the server. The vulnerability is based on CWE‑22 and permits removal of files outside the plugin’s designated storage area, potentially deleting critical configuration or system files and disrupting site operation.
Affected Systems
The affected product is Woo File Dropzone, a WordPress plugin developed by Murtaza Bhurgri. Versions up to and including 1.1.7 are impacted, while later revisions are presumed fixed.
Risk and Exploitability
The assigned CVSS score of 7.7 indicates high severity, and an EPSS score of less than 1 % suggests exploitation is unlikely in the near term. The vulnerability is listed as not present in the CISA KEV catalog, thus no evidence of widespread exploitation is known. Based on the description, the likely attack vector involves a web request that leverages the path traversal flaw; a remote attacker could trigger file deletions by constructing a specially crafted URL to the plugin’s deletion endpoint.
OpenCVE Enrichment