
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22448 is a Path Traversal (Arbitrary File Deletion) vulnerability in the PitchPrint WordPress plugin developed by flexcubed. It affects all versions of the plugin up to and including 11.1.2, and was reported on December 9, 2025, with public disclosure on March 10–25, 2026. The vulnerability carries a CVSS v3.1 base score of 7.5 (High), exploitable by unauthenticated remote attackers (Patchstack, Feedly).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'). Due to insufficient validation of user-supplied file path inputs, an unauthenticated attacker can craft requests that traverse outside the intended directory boundaries and trigger deletion of arbitrary files on the server. No authentication or user interaction is required, and the attack is conducted entirely over the network. No public proof-of-concept code has been identified at this time (Patchstack, Feedly).
Successful exploitation allows an unauthenticated attacker to delete arbitrary files from the WordPress server's file system. Deletion of WordPress core files, configuration files (e.g., wp-config.php), or plugin/theme files can render the website completely non-functional, resulting in a denial-of-service condition. While the CVSS score reflects no direct confidentiality or integrity impact, targeted deletion of critical files could facilitate further attacks such as site takeover or data loss (Patchstack).
No confirmed in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of exploitation in the near term. The vulnerability requires no authentication or user interaction, making it accessible to any remote attacker, and Patchstack has flagged it as high priority with potential for mass-exploit campaigns targeting WordPress sites at scale. It does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Patchstack, Feedly).
/wp-content/plugins/pitchprint/readme.txt.../../wp-config.php or ../../../index.php) in the file path parameter to reference files outside the plugin's intended directory.wp-config.php), which may cause site outage, expose database credentials on re-setup, or facilitate further compromise (Patchstack)./wp-admin/admin-ajax.php with PitchPrint-specific action parameters) containing path traversal sequences such as ../, ..%2F, or URL-encoded variants.wp-config.php, index.php, or core plugin/theme files; file system audit logs recording deletions by the web server process (e.g., www-data) outside normal operational patterns.The vendor has released version 11.2.0 of the PitchPrint plugin, which patches this vulnerability. All users running version 11.1.2 or earlier should update to 11.2.0 or later immediately via the WordPress plugin dashboard. Patchstack has also issued a virtual patching/mitigation rule for its subscribers that blocks both legitimate and illegitimate exploitation attempts until the plugin is updated. If immediate updating is not possible, consider temporarily deactivating the PitchPrint plugin or consulting your hosting provider (Patchstack).
Patchstack, which discovered and disclosed the vulnerability (credited to researcher NumeX), classified it as high priority and noted its potential for use in mass-exploit campaigns against WordPress sites. Wordfence also referenced the vulnerability in its weekly WordPress vulnerability report for the period of March 9–15, 2026. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database listings (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."