Arbitrary Directory Deletion in Eleganzo Theme for WordPress
CVE-2025-15470
6.5MEDIUM
What is CVE-2025-15470?
The Eleganzo theme for WordPress is affected by a vulnerability that allows authenticated users with Subscriber-level access to delete arbitrary directories on the server. This issue arises from inadequate path validation within the akd_required_plugin_callback function present in all versions up to and including 1.2. An attacker could leverage this flaw to compromise the integrity of the website by removing critical files and potentially gaining access to sensitive information.
Affected Version(s)
Eleganzo 0 <= 1.2