Description
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the LSD_Menus_IX_CSV::import function in all versions up to, and including, 6.1.2 This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Published: 2026-10-10
Score: 4.9 Medium
EPSS: n/a
KEV: No
Impact: Remote Code Execution via Arbitrary File Deletion
Action: Update Plugin
AI Analysis

Impact

The vulnerability in Listdom allows an authenticated attacker with administrator or higher privileges to supply a crafted 'ix[file]' parameter that bypasses file path validation. This leads to arbitrary deletion of server files, including critical ones such as wp-config.php, which can in turn enable remote code execution or result in total site compromise. The weakness stems from improper path traversal filtering, identified as CWE-22.

Affected Systems

All installations of the Listdom plugin for WordPress up to and including version 6.1.2 are affected. Administrators and users with equivalent privileges are capable of triggering the deletion when they access the affected import function. The plugin is available from the WordPress plugin repository under the vendor webilia.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated access at the administrator level, the attack surface is limited to sites with compromised or poorly secured admin credentials. Once authenticated, an attacker can delete arbitrary files, and if the deletion removes configuration files, it may lead to remote code execution. Given the moderate CVSS and the necessity of elevated privileges, the likelihood of exploitation exists but is not high without privileged access.

Generated by OpenCVE AI on October 10, 2026 at 09:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Listdom to a version newer than 6.1.2, which removes the vulnerable import functionality.
  • If an upgrade cannot be applied immediately, temporarily disable or remove the import feature that processes the 'ix[file]' parameter.
  • Restrict administrator account permissions and enforce strong multi‑factor authentication to prevent unauthorized use of the vulnerable functionality.
  • Apply file system permissions that prevent deletion of critical files and monitor logs for suspicious delete operations.

Generated by OpenCVE AI on October 10, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the LSD_Menus_IX_CSV::import function in all versions up to, and including, 6.1.2 This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Title Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.2 - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'ix[file]' Parameter
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T08:26:39.464Z

Reserved: 2026-10-02T11:44:39.625Z

Link: CVE-2026-104722

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T09:16:37.863

Modified: 2026-10-10T09:16:37.863

Link: CVE-2026-104722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:30:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')