Description
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
Published: 2026-06-29
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to delete arbitrary files via the WordPress Paid Videochat Turnkey Site plugin. It stems from improper validation of file paths and is identified as CWE‑22. An attacker who exploits this flaw can remove essential configuration or content files, leading to data loss, service disruption, and possible further compromise if other weaknesses exist.

Affected Systems

The affected product is Videowhispers’ Paid Videochat Turnkey Site plugin, versions up to and including 7.4.8. No more granular version data is provided in the source information.

Risk and Exploitability

The CVSS score of 9.9 classifies this as a critical vulnerability with very high impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is remote via the web interface, and privileged access or an elevated user role may be required to trigger the deletion operation.

Generated by OpenCVE AI on June 29, 2026 at 17:06 UTC.

Remediation

Vendor Solution

Update the WordPress Paid Videochat Turnkey Site Plugin to the latest available version (at least 7.4.9).


OpenCVE Recommended Actions

  • Update the Paid Videochat Turnkey Site plugin to version 7.4.9 or later – this is the official vendor fix.
  • Restrict the deletion capability by limiting the feature to trusted administrators or disabling it entirely if unnecessary – this mitigates the attack surface in line with CWE‑22 principles.
  • Ensure file system permissions for the web application are tightly controlled so that only required directories are writable, preventing arbitrary deletion of critical files.

Generated by OpenCVE AI on June 29, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Videowhisper.com
Videowhisper.com paid Videochat Turnkey Site
Wordpress
Wordpress wordpress
Vendors & Products Videowhisper.com
Videowhisper.com paid Videochat Turnkey Site
Wordpress
Wordpress wordpress

Mon, 29 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
Description Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
Title WordPress Paid Videochat Turnkey Site plugin <= 7.4.8 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Videowhisper.com Paid Videochat Turnkey Site
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-29T15:19:37.044Z

Reserved: 2026-06-24T12:45:08.530Z

Link: CVE-2026-57331

cve-icon Vulnrichment

Updated: 2026-06-29T14:58:32.108Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T10:04:28Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')