Ovatheme Movie Booking Path Traversal Vulnerability Allowing Arbitrary File Deletion

Vulnerability

A path traversal vulnerability has been identified in the Ovatheme Movie Booking WordPress plugin, specifically in versions through 1.1.5. This vulnerability allows for improper limitation of a pathname to a restricted directory, enabling arbitrary file deletion. Exploiting this issue could lead to the deletion of critical files from a website, potentially causing the site to malfunction or break.

Impact

Exploitation of this vulnerability could result in the deletion of arbitrary files from the affected WordPress site. If core files are removed, it could disrupt the site's functionality and cause it to stop working properly.

Remediation

Users of the Ovatheme Movie Booking WordPress plugin should update to version 1.1.6 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.

Added: Jan 22, 2026, 6:01 PM
Updated: Jan 22, 2026, 6:01 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
7.0
remediation
0.0
relevance
2.3
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.