Arbitrary File Deletion in Listdom: AI-Powered Business Directory Plugin for WordPress
CVE-2026-104722

4.9MEDIUM

What is CVE-2026-104722?

The Listdom plugin for WordPress is susceptible to an arbitrary file deletion vulnerability stemming from inadequate file path validation within the LSD_Menus_IX_CSV::import function. This issue affects all versions up to and including 6.1.2. With administrator-level access, authenticated attackers can exploit this weakness to delete critical files from the server, potentially leading to remote code execution if sensitive files, like wp-config.php, are removed. It is crucial for users to update to the latest version to mitigate this risk and secure their environments.

Affected Version(s)

Listdom: AI-powered Business Directory with Classifieds Ads Listings 0 <= 6.1.2

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.