Arbitrary File Deletion in Paid Videochat Turnkey Site by Patchstack
CVE-2026-57331

9.9CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 June 2026

What is CVE-2026-57331?

The Paid Videochat Turnkey Site, specifically versions up to 7.4.8, is vulnerable to arbitrary file deletion. This flaw can allow attackers to remove critical files from the server, leading to potential loss of sensitive data and system integrity. Administrators are urged to apply updates and mitigate risks associated with this vulnerability.

Affected Version(s)

Paid Videochat Turnkey Site <= 7.4.8

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

endy | Patchstack Bug Bounty Program
.