CVE-2025-15470

⚪ Do wiadomości

Luka w motywie Eleganzo dla WordPressa pozwala na usunięcie dowolnych katalogów przez uwierzytelnionych atakujących.

CVSS
6.5
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in the akd_required_plugin_callback function in all versions up to, and including, 1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary directories on the server, including the WordPress root directory.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-04-15 04:17:20 UTC
Ostatnia modyfikacja (NVD)2026-10-07 09:10:00 UTC
Referencje