Description
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
Published: 2026-07-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WordPress Broadcast Live Video plugin version 7.2.4 and earlier contains a flaw that allows an attacker to delete arbitrary files on the web server. The official CVE description indicates unauthenticated deletion. Based on the description, it is inferred that the plugin’s delete endpoint does not perform credential checks, allowing specified file paths to be removed. This weakness is classified as CWE‑22, reflecting unauthorized file deletion.

Affected Systems

WordPress sites that have installed videowhisper’s Broadcast Live Video plugin 7.2.4 or older are affected. No other vendors or products are listed, and the issue is confined to this plugin in WordPress environments.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity, while the EPSS score of less than 1 % points to a low probability of exploitation at this time. The vulnerability is not included in the CISA KEV catalog. The likely attack vector is remote HTTP requests to the plugin’s delete endpoint; this inference is based on the flaw being unauthenticated and the plugin’s operation within a web server environment.

Generated by OpenCVE AI on August 3, 2026 at 22:26 UTC.

Remediation

Vendor Solution

Update the WordPress Broadcast Live Video Plugin to the latest available version (at least 7.2.5).


OpenCVE Recommended Actions

  • Update the Broadcast Live Video Plugin to at least version 7.2.5.
  • Reconfigure file system permissions so that the web server process cannot delete arbitrary files used by the plugin.
  • Deploy a web application firewall or similar rule set to detect and block unauthorized delete requests to the plugin’s endpoint.

Generated by OpenCVE AI on August 3, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Videowhisper
Videowhisper broadcast Live Video
Wordpress
Wordpress wordpress
Vendors & Products Videowhisper
Videowhisper broadcast Live Video
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
Title WordPress Broadcast Live Video plugin <= 7.2.4 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Videowhisper Broadcast Live Video
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:23:10.923Z

Reserved: 2026-06-25T08:04:04.790Z

Link: CVE-2026-57716

cve-icon Vulnrichment

Updated: 2026-07-23T14:23:04.299Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:29.800

Modified: 2026-07-23T15:17:21.050

Link: CVE-2026-57716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:30:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')