Description
Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.
Published: 2026-08-24
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Deletion (Availability/Integrity)
Action: Apply Patch
AI Analysis

Impact

ShopBuilder Pro – Elementor WooCommerce Builder Addons versions up to 2.2.0 allow an unauthenticated user to delete arbitrary files on the server. The vulnerability is triggered by an insecure deletion endpoint that does not verify user privileges, enabling attackers to remove critical files such as configuration or plugin files. Successful exploitation can result in loss of data, disruption of website functionality, and potential code execution if core files are removed, thereby compromising confidentiality, integrity, and availability.

Affected Systems

The affected product is RadiusTheme's ShopBuilder Pro – Elementor WooCommerce Builder Addons plugin for WordPress. All releases with a version number 2.2.0 or earlier are susceptible. No specific sub‑versions are listed, so any build bundled with 2.2.0 or earlier is at risk.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. While an EPSS score is not available, the lack of publicly known exploitation reduces the certainty of immediate attacks but does not diminish the potential impact. The vulnerability is not listed in the CISA KEV catalog, yet its ability to delete arbitrary files makes it a serious threat to any site deploying the affected plugin. A naive HTTP request to the deletion endpoint can trigger the flaw, implying that any exposed WordPress instance running the vulnerable plugin is highly vulnerable.

Generated by OpenCVE AI on August 24, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official update for ShopBuilder Pro – Elementor WooCommerce Builder Addons to a version newer than 2.2.0
  • If an update is not available, disable or remove the plugin to eliminate the deletion vector
  • Configure file system permissions to prevent unprivileged deletion and monitor access logs for unauthorized deletion attempts
  • Contact RadiusTheme for a patch or advisory if none is released

Generated by OpenCVE AI on August 24, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Radiustheme
Radiustheme shopbuilder – Elementor Woocommerce Builder Addons
Wordpress
Wordpress wordpress
Vendors & Products Radiustheme
Radiustheme shopbuilder – Elementor Woocommerce Builder Addons
Wordpress
Wordpress wordpress

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.
Title WordPress ShopBuilder Pro – Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Radiustheme Shopbuilder – Elementor Woocommerce Builder Addons
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T12:51:07.579Z

Reserved: 2026-03-12T11:11:50.222Z

Link: CVE-2026-32477

cve-icon Vulnrichment

Updated: 2026-08-24T12:48:19.080Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T12:16:51.473

Modified: 2026-08-24T16:40:53.647

Link: CVE-2026-32477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:45:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')