Impact
The vulnerability allows an unauthenticated attacker to delete any file on the server that the WordPress installation can access. This is a path traversal flaw, identified as CWE-22, and it removes files from the web server, potentially taking critical plugins, themes, or system files down and resulting in loss of data and application availability.
Affected Systems
It affects the AcyMailing SMTP Newsletter plugin for WordPress, versions 11.0.5 and earlier. Sites that have the plugin installed and are exposed to the internet are at risk. WordPress installations running these versions have the vulnerable component and should be updated.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating high severity. No EPSS score is available, so the current exploitation probability cannot be determined, but the high CVSS suggests that if exploited it would be catastrophic. The vulnerability is not listed in CISA’s KEV catalog, but the lack of mitigation does not reduce its risk. An attacker can trigger the deletion by sending an unauthenticated request to the plugin’s endpoint that accepts a file path as a parameter.
OpenCVE Enrichment