CVE-2026-57346 HIGH

CVE-2026-57346: WordPress Embed Privacy plugin <= 1.12.3 - Arbitrary File Deletion vulnerability

Vendor Epiphyt
Product Embed Privacy
Weakness CWE-22 · Path traversal
Published June 29, 2026
Last update June 29, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

What the vulnerability does

01Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.

Explanation of Vulnerability in Simple Terms

02Summary

Embed Privacy versions up to 1.12.3 contain a path traversal vulnerability that allows authenticated users to manipulate file paths and cause the site to become unavailable. An attacker with low-level access can bypass directory restrictions and trigger a denial-of-service condition. No confidentiality breach occurs, but integrity and availability are compromised.

What an attacker can do

03Attacker Capabilities

Make the site unavailable or corrupt files by manipulating file paths.

Potential impact on your site

04Site Impact

Site downtime or file corruption if a user account is compromised or misused.

Conditions required to exploit

05Prerequisites

Attacker must have a low-level user account on the site.

Key dates

06Disclosure timeline

June 29, 2026 CVE published
June 29, 2026 Record updated