Impact
The vulnerability is an unauthenticated arbitrary file deletion flaw in the WooCommerce File Approval plugin up to version 10.7. An attacker can leverage the plugin’s file handling logic to delete any file that the web server can write to, resulting in data loss and potential disruption of site functionality. This flaw is a classic example of CWE‑22, where uncontrolled file paths enable deletion of arbitrary files.
Affected Systems
Affected are WordPress sites that use the vanquish WooCommerce File Approval plugin at any release prior to 10.8. No further sub‑version detail is listed, so all builds <=10.7 are considered vulnerable. The product is a WordPress plugin that extends WooCommerce with file approval capabilities, and the flaw exists in its file deletion routine.
Risk and Exploitability
The CVSS score of 8.6 classifies this as high severity, but EPSS data is not available, so the current exploit probability is unknown. The vulnerability is unauthenticated, which suggests the attack vector most likely originates from an unauthenticated HTTP request to the plugin. Because the flaw can delete any accessible file, the risk to confidentiality and integrity is significant, yet the lack of KEV listing means no publicly documented exploit code is known.
OpenCVE Enrichment