Impact
The WordPress Broadcast Live Video plugin version 7.2.4 and earlier contains a flaw that allows an attacker to delete arbitrary files on the web server. The official CVE description indicates unauthenticated deletion. Based on the description, it is inferred that the plugin’s delete endpoint does not perform credential checks, allowing specified file paths to be removed. This weakness is classified as CWE‑22, reflecting unauthorized file deletion.
Affected Systems
WordPress sites that have installed videowhisper’s Broadcast Live Video plugin 7.2.4 or older are affected. No other vendors or products are listed, and the issue is confined to this plugin in WordPress environments.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity, while the EPSS score of less than 1 % points to a low probability of exploitation at this time. The vulnerability is not included in the CISA KEV catalog. The likely attack vector is remote HTTP requests to the plugin’s delete endpoint; this inference is based on the flaw being unauthenticated and the plugin’s operation within a web server environment.
OpenCVE Enrichment