Impact
The FunnelKit WordPress plugin before version 3.15.0.6 allows an administrator to delete arbitrary files when importing a template. The deletion function does not validate the supplied file path, so a malicious or compromised admin can provide a path that traverses out of the intended directory, removing .json files outside the plugin's scope. This operation can break the plugin's configuration or cause a denial of service by rendering the plugin inoperable.
Affected Systems
Any WordPress installation that includes the FunnelKit plugin with a version older than 3.15.0.6. The vulnerability is specific to the FunnelKit plugin for WordPress and affects users who have administrator-level access to the site.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk, with an EPSS score of less than 1% showing a very low likelihood of exploitation in the wild. The vulnerability is not currently listed in CISA's KEV catalog. Exploitation requires administrative privileges; an attacker needs to be able to perform a template import with a crafted file path. No remote code execution or data exfiltration is possible, but an exploit leads to service interruption by deleting critical configuration files.
OpenCVE Enrichment