Impact
The PeepSo plugin for WordPress contains a path traversal flaw that lets an authenticated subscriber delete any file located on the server. By submitting a specially crafted deletion request that supplies a manipulated file path, the attacker can remove configuration files, media uploads, or other critical content, thereby corrupting data integrity and potentially disrupting site availability.
Affected Systems
All WordPress sites running PeepSo version 9.0.5.4 or earlier are affected. The vulnerability resides in the file deletion endpoint exposed to users who have subscriber level access; no other WordPress components are implicated by the advisory.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity risk. No EPSS data exists, but because any user who registers as a subscriber can trigger the flaw, the likelihood of exploitation is significant for sites with open registration or accepting registrations arbitrarily. The vulnerability is not listed in CISA KEV, suggesting no publicly documented exploits yet. The attack vector is inferred to involve an attacker creating or obtaining subscriber access, then submitting a malicious deletion request that exploits the path traversal logic to remove arbitrary files.
OpenCVE Enrichment