Arbitrary File Deletion Vulnerability in LWS Cleaner Plugin for WordPress
CVE-2025-8575
7.2HIGH
What is CVE-2025-8575?
The LWS Cleaner plugin, designed for WordPress, has a significant vulnerability that stems from inadequate validation of file paths in its 'lws_cl_delete_file' function. This flaw allows authenticated users, specifically those with Administrator-level access, to delete arbitrary files from the server. Such actions can pose severe consequences, including the potential for remote code execution if critical files, like wp-config.php, are removed. It is crucial for site administrators to address this vulnerability to safeguard their installations.
Affected Version(s)
LWS Cleaner * <= 2.4.1.3