Impact
ShopBuilder Pro – Elementor WooCommerce Builder Addons versions up to 2.2.0 allow an unauthenticated user to delete arbitrary files on the server. The vulnerability is triggered by an insecure deletion endpoint that does not verify user privileges, enabling attackers to remove critical files such as configuration or plugin files. Successful exploitation can result in loss of data, disruption of website functionality, and potential code execution if core files are removed, thereby compromising confidentiality, integrity, and availability.
Affected Systems
The affected product is RadiusTheme's ShopBuilder Pro – Elementor WooCommerce Builder Addons plugin for WordPress. All releases with a version number 2.2.0 or earlier are susceptible. No specific sub‑versions are listed, so any build bundled with 2.2.0 or earlier is at risk.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. While an EPSS score is not available, the lack of publicly known exploitation reduces the certainty of immediate attacks but does not diminish the potential impact. The vulnerability is not listed in the CISA KEV catalog, yet its ability to delete arbitrary files makes it a serious threat to any site deploying the affected plugin. A naive HTTP request to the deletion endpoint can trigger the flaw, implying that any exposed WordPress instance running the vulnerable plugin is highly vulnerable.
OpenCVE Enrichment