JKDEVKIT WordPress Plugin Arbitrary File Deletion Vulnerability

Vulnerability

A vulnerability allowing arbitrary file deletion has been identified in the JKDEVKIT plugin for WordPress, affecting all versions through 1.9.4. This issue arises from inadequate file path validation in the 'font_upload_handler' function. The vulnerability enables authenticated attackers with Subscriber-level access and above to delete arbitrary files on the server. Deleting certain files, such as wp-config.php, could lead to remote code execution. If WooCommerce is active, a minimum of Contributor-level access is required.

Impact

Exploitation of this vulnerability could result in unauthorized deletion of files on the server, potentially leading to remote code execution if a critical file is removed.

Added: Jul 3, 2025, 1:25 PM
Updated: Jul 3, 2025, 3:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
0.0
relevance
0.2
threat
0.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.