Home Villas Real Estate WordPress Theme Arbitrary File Deletion Vulnerability

Vulnerability

A vulnerability allowing arbitrary file deletion has been identified in the Home Villas | Real Estate WordPress Theme, affecting all versions through 2.8. This issue arises from inadequate validation of file paths in the 'wp_rem_cs_widget_file_delete' function. As a result, authenticated attackers with Subscriber-level access or higher can delete arbitrary files from the server. This vulnerability could easily lead to remote code execution if a critical file, such as wp-config.php, is deleted.

Impact

Exploitation of this vulnerability could result in unauthorized deletion of files on the server, potentially leading to remote code execution if a sensitive file is removed.

Remediation

No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected theme.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.9
remediation
0.0
relevance
0.2
threat
3.3
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.