Impact
The vulnerability in Listdom allows an authenticated attacker with administrator or higher privileges to supply a crafted 'ix[file]' parameter that bypasses file path validation. This leads to arbitrary deletion of server files, including critical ones such as wp-config.php, which can in turn enable remote code execution or result in total site compromise. The weakness stems from improper path traversal filtering, identified as CWE-22.
Affected Systems
All installations of the Listdom plugin for WordPress up to and including version 6.1.2 are affected. Administrators and users with equivalent privileges are capable of triggering the deletion when they access the affected import function. The plugin is available from the WordPress plugin repository under the vendor webilia.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated access at the administrator level, the attack surface is limited to sites with compromised or poorly secured admin credentials. Once authenticated, an attacker can delete arbitrary files, and if the deletion removes configuration files, it may lead to remote code execution. Given the moderate CVSS and the necessity of elevated privileges, the likelihood of exploitation exists but is not high without privileged access.
OpenCVE Enrichment