Sceawere
Vulnerability Detail
CVE-2026-104722UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Arbitrary File Deletion in Listdom
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.9
- Creation Date
- 3h ago
- Vendor
- webilia
- Product
- Listdom: AI-powered Business Directory with Classifieds Ads Listings
- Attack Type
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the LSD_Menus_IX_CSV::import function in all versions up to, and including, 6.1.2 This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.9",
"pubDate": "2026-10-10T09:16:37.863Z",
"pubdate": "2026-10-10T09:16:37.863Z",
"executiveSummary": "The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is affected by an arbitrary file deletion vulnerability in versions up to, and including, 6.1.2. The vulnerability stems from insufficient validation of file paths within the LSD_Menus_IX_CSV::import function.\nSuccessful exploitation allows an authenticated attacker with administrator-level privileges to delete arbitrary files on the web server filesystem. By targeting critical system or configuration files, such as 'wp-config.php', an attacker can facilitate a complete site takeover, leading to remote code execution or permanent denial of service. This vulnerability poses a critical risk to the integrity and availability of the affected WordPress installation.\nExploitation requires administrative access, limiting the attack vector to high-privileged accounts. However, the impact is severe, as it enables the deletion of core components required for site operation, which can then be leveraged to reconfigure the environment or execute arbitrary code through subsequent installation or setup procedures.",
"technicalDetails": "The vulnerability resides within the 'LSD_Menus_IX_CSV::import' function, which fails to adequately sanitize or validate user-supplied file path inputs before processing deletion operations. In WordPress environments, such functions often handle temporary file cleanup or CSV processing; however, in this instance, the implementation does not restrict file operations to expected directories or file types.\nThe root cause is a path traversal or unchecked file manipulation flaw. Because the application logic does not employ a whitelist or adequate path canonicalization, an attacker can manipulate the input parameters passed to this function. By supplying an absolute or relative path to a sensitive file, the attacker forces the underlying system API (typically 'unlink()') to remove the target file from the server's storage.\nThe attack flow proceeds as follows: First, the attacker authenticates as a WordPress administrator. Second, the attacker interacts with the 'LSD_Menus_IX_CSV::import' function, likely via an imported CSV configuration or a direct request to the vulnerable endpoint, substituting legitimate file paths with the path to a critical system file (e.g., '/var/www/html/wp-config.php').\nUpon triggering the vulnerable function, the application executes a deletion command against the specified path. Deleting 'wp-config.php' is particularly critical, as it removes the database connection credentials and security keys. In many shared hosting environments, the deletion of this file forces the application into a re-installation state or causes the site to crash, providing the attacker with a window to point the application to a malicious database or execute code through the setup wizard.\nThis vulnerability is restricted to versions up to, and including, 6.1.2. The lack of integrity checking allows the 'unlink' operation to proceed without checking ownership or filesystem boundaries, effectively granting the attacker the same file-level permissions as the web server user. The vulnerability is highly exploitable provided the attacker possesses the necessary administrative credentials to access the plugin’s CSV import administrative interface."
}