The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post metadata: the value passes only through wp_strip_all_tags() (which does not strip path traversal sequences), is stored directly in post meta, and is later concatenated without normalization into a filesystem path in getFullImgPath() before being passed to PHP's unlink(). This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the affected site's server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 13:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-05T14:40:28.082Z
Reserved: 2026-07-16T16:28:59.312Z
Link: CVE-2026-15979
Updated: 2026-08-05T14:40:18.375Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T15:15:05Z