Path Traversal Vulnerability in Sucuri Security WordPress Plugin
CVE-2026-73033
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 10 August 2026
Badges
What is CVE-2026-73033?
The Sucuri Security WordPress plugin, up to version 2.7.3, suffers from a path traversal vulnerability within the pageIntegritySubmission() method in src/integrity.lib.php. This flaw enables authenticated administrators to delete arbitrary files by inserting directory traversal sequences into the sucuriscan_integrity parameter. Attackers can exploit this by manipulating an unsanitized file path, allowing navigation outside the intended WordPress installation directory. This manipulation can lead to the deletion of sensitive files, including wp-config.php and .htaccess, potentially leading to site outages or enabling the malicious reinstallation of software.
Affected Version(s)
sucuri-wordpress-plugin 0 <= 2.7.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved