Impact
The vulnerability is a Path Traversal flaw (CWE-22) that allows an attacker to supply a crafted file path and delete arbitrary files on the web server. By bypassing the plugin's directory restrictions, the attacker can remove critical application files, configuration files, or data, leading to loss of data, service disruption, and potentially enabling further exploitation if key plugins or scripts are removed.
Affected Systems
The affected product is Brainstorm Force's SureDash WordPress plugin. All releases from the initial version through 1.8.0 are vulnerable. Site administrators running any of these versions, enabled, are at risk.
Risk and Exploitability
The CVSS score of 9.9 indicates full confidentiality, integrity, and availability impact can be achieved by a remote attacker with network access to the WordPress site. The EPSS score of < 1% suggests a low current probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote endpoint. An attacker would need to craft a specially constructed request, typically through the WordPress admin interface or any exposed file manipulation API, to trigger the deletion outside the intended directory.
OpenCVE Enrichment