Impact
The vulnerability is an improper limitation of a pathname to a restricted directory, allowing an attacker to traverse directories and delete arbitrary files. The flaw can be used to remove files from the web server, destroying critical data, disrupting service, and potentially exposing sensitive information. The associated weakness is Path Traversal (CWE‑22).
Affected Systems
Vendor Adrian Tobey’s Groundhogg WordPress plugin is affected, from its initial release through version 4.4.1. Any site running the plugin on or before that version is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 8.6, the defect represents high severity and the EPSS score indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote, file deletion.
OpenCVE Enrichment