Arbitrary File Deletion in Listdom: AI-Powered Business Directory Plugin for WordPress
CVE-2026-104722
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-104722?
The Listdom plugin for WordPress is susceptible to an arbitrary file deletion vulnerability stemming from inadequate file path validation within the LSD_Menus_IX_CSV::import function. This issue affects all versions up to and including 6.1.2. With administrator-level access, authenticated attackers can exploit this weakness to delete critical files from the server, potentially leading to remote code execution if sensitive files, like wp-config.php, are removed. It is crucial for users to update to the latest version to mitigate this risk and secure their environments.
Affected Version(s)
Listdom: AI-powered Business Directory with Classifieds Ads Listings 0 <= 6.1.2