Sceawere
Vulnerability Detail
CVE-2026-96824UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Template Kit Arbitrary File Deletion
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 3h ago
- Vendor
- envato
- Product
- Template Kit – Import
- Attack Type
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-09-30T13:17:32.083Z",
"pubdate": "2026-09-30T13:17:32.083Z",
"executiveSummary": "Template Kit – Import versions 1.0.16 and below are susceptible to an arbitrary file deletion vulnerability. This flaw allows an authenticated attacker to delete critical files from the underlying server filesystem by manipulating inputs within the plugin's file handling processes.\nThe vulnerability is classified as an improper neutralization of input during file system operations. Successful exploitation can lead to a complete compromise of the application's availability and integrity, potentially resulting in a denial-of-service (DoS) state or the removal of security-critical configuration files like wp-config.php, which may facilitate further exploitation such as remote code execution or unauthorized installation.\nThis vulnerability resides within the plugin's file management logic. It requires an attacker to possess valid authentication credentials to interact with the vulnerable functionality. Because the plugin processes user-supplied file paths without adequate sanitization or boundary validation, the attacker can traverse outside the intended directory to target arbitrary files on the web server. Organizations should prioritize updating to the latest secure version of the plugin or disabling the functionality until a patch is applied to mitigate the risk of catastrophic system failure.",
"technicalDetails": "The vulnerability exists due to a lack of proper input validation and path sanitization in the file handling routines of the Template Kit – Import plugin. Specifically, the component responsible for processing import tasks fails to enforce strict path restrictions when handling delete requests initiated by the user. By failing to validate the provided input against an expected base directory or whitelist, the plugin allows for directory traversal sequences (e.g., ../) to be injected into the file path parameter.\nThe attack flow begins when an attacker, possessing administrative or sufficient privileges, triggers the file deletion action provided by the plugin. During this process, the plugin accepts a user-controlled parameter containing the path to the target file. Because the application logic does not sufficiently sanitize this input to prevent traversal, the attacker can supply a crafted path that resolves to sensitive system files, application core files, or configuration files outside of the plugin's temporary upload directory.\nOnce the attacker submits the malicious request, the server-side script resolves the path and executes a file deletion function (such as unlink() in PHP) on the target file. If the web server process has sufficient file system permissions to access and delete the target file, the file is immediately removed from the disk. This behavior is not restricted to the plugin’s intended scope; it can target any location on the filesystem that the web server user (e.g., www-data) is permitted to modify.\nThe post-exploitation impact is severe. By deleting wp-config.php, an attacker can trigger the WordPress installation process, potentially allowing them to reconfigure the database connection to an attacker-controlled instance or perform a secondary takeover of the site. Furthermore, the deletion of critical core files, theme files, or plugin files will inevitably cause a persistent denial-of-service, rendering the affected application non-functional and potentially creating a window for further exploitation. The vulnerability is effective across all versions up to and including 1.0.16. There is no indication that the vulnerability is exploitable by unauthenticated users, though it remains a significant risk for environments with multiple administrators or compromised low-level accounts."
}