Vikinger WordPress Theme Arbitrary File Deletion Vulnerability
Vulnerability
A vulnerability allowing arbitrary file deletion has been identified in the Vikinger theme for WordPress, in all versions through 1.9.32. This issue arises from inadequate file path validation in the 'vikinger_delete_activity_media_ajax' function. As a result, authenticated attackers with Subscriber-level access or higher can delete arbitrary files on the server. This vulnerability could easily lead to remote code execution if a critical file, such as 'wp-config.php', is deleted. It is important to note that the Vikinger Media plugin must be installed and active for this vulnerability to be exploited.
Impact
Exploitation of this vulnerability allows for arbitrary file deletion on the server, which could lead to remote code execution if a sensitive file is removed.
Remediation
Users are advised to update the Vikinger theme to version 1.9.33 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
