{"id":"CVE-2026-15979","published":"2026-08-05T14:17:03.547","lastModified":"2026-08-05T16:16:51.530","description":"The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post metadata: the value passes only through wp_strip_all_tags() (which does not strip path traversal sequences), is stored directly in post meta, and is later concatenated without normalization into a filesystem path in getFullImgPath() before being passed to PHP's unlink(). This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the affected site's server which may make remote code execution possible.","cvssScore":8.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://plugins.trac.wordpress.org/browser/content-egg/tags/11.2.0/application/admin/EggMetabox.php#L372","tags":[]},{"url":"https://plugins.trac.wordpress.org/browser/content-egg/tags/11.2.0/application/components/ContentManager.php#L161","tags":[]},{"url":"https://plugins.trac.wordpress.org/browser/content-egg/tags/11.2.0/application/components/ContentManager.php#L200","tags":[]},{"url":"https://plugins.trac.wordpress.org/browser/content-egg/tags/11.2.0/application/helpers/ImageHelper.php#L149","tags":[]},{"url":"https://plugins.trac.wordpress.org/browser/content-egg/tags/11.3.0/application/admin/EggMetabox.php#L372","tags":[]},{"url":"https://plugins.trac.wordpress.org/browser/content-egg/tags/11.3.0/application/components/ContentManager.php#L161","tags":[]},{"url":"https://plugins.trac.wordpress.org/browser/content-egg/tags/11.3.0/application/components/ContentManager.php#L200","tags":[]},{"url":"https://plugins.trac.wordpress.org/browser/content-egg/tags/11.3.0/application/helpers/ImageHelper.php#L149","tags":[]},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3610612%40content-egg%2Ftrunk%2Fapplication%2Fhelpers%2FImageHelper.php&old=3514579%40content-egg%2Ftrunk%2Fapplication%2Fhelpers%2FImageHelper.php","tags":[]},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bc1600b9-b590-47ca-b2d9-d521381da541?source=cve","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows authenticated attackers with author-level access to delete arbitrary files via path traversal, potentially leading to remote code execution.","exploitability":"Exploitation is moderately difficult requiring author-level access and knowledge of specific file paths.","blast_radius":"If exploited, the impact could be severe as it may lead to full server compromise through RCE.","remediation":"Update to the latest version of Content Egg – Affiliate Product Importer & Price Comparison plugin immediately.","tags":["rce","auth-bypass","web","file-deletion","wordpress"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:50:45.456Z"}}