Impact
The vulnerability is an improper limitation of a pathname to a restricted directory (Path Traversal). By manipulating input, an attacker can delete arbitrary files on the server’s filesystem, potentially removing critical data or disrupting the application’s operation.
Affected Systems
All releases of the WordPress Embed Privacy plugin provided by Epiphyt, from the earliest version through 1.12.3, are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk. No exploitation probability score is available and the flaw is not listed in CISA’s KEV catalog, suggesting it has not yet been exploited at scale, though that does not reduce its potential impact. Based on the description, it is inferred that the attack could be carried out remotely via the plugin’s web interface, possibly requiring administrative privileges or some level of authenticated access to the WordPress site. The risk remains significant until the plugin is updated or disabled.
OpenCVE Enrichment