SMSA Express SMSA Shipping Path Traversal Vulnerability Allowing Arbitrary File Deletion

Vulnerability

A path traversal vulnerability has been identified in the SMSA Express SMSA Shipping WordPress plugin, affecting versions through 2.3. This vulnerability allows for arbitrary file deletion, which could lead to the removal of critical files from a website, potentially causing the site to malfunction.

Impact

Exploitation of this vulnerability could result in the deletion of arbitrary files from the affected WordPress site. If essential core files are removed, it could disrupt the site's functionality and cause it to break.

Remediation

Users of the SMSA Shipping WordPress plugin should update to version 2.4 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.