Critical CVE-2026-57331 Allows Arbitrary File Deletion in Videochat Plugin
ID: 93191359-5be5-5fa9-81f3-6cfca821d206
STIX ID: report--93191359-5be5-5fa9-81f3-6cfca821d206
Feed Name: ThreatCluster
Threat Score
A critical path traversal vulnerability (CVE-2026-57331, CVSS 9.9) in the Paid Videochat Turnkey Site WordPress plugin (<=7.4.8) allows authenticated performer users to delete arbitrary files; immediate upgrade to version 7.4.9+, restriction of performer permissions, and file-system monitoring are recommended, and no public exploitation has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
