CVE-2026-31913: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-31913 is a Path Traversal (Arbitrary File Deletion) vulnerability in the Whitebox-Studio Scape WordPress theme that allows unauthenticated remote attackers to delete arbitrary files on the server. It affects all Scape theme versions prior to 1.5.16 and was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on February 5, 2026, with public disclosure on March 20–25, 2026. The vulnerability carries a CVSS v3.1 base score of 8.6 (High) (Patchstack, Feedly).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and manifests as an arbitrary file deletion capability within the Scape WordPress theme. Due to insufficient validation of user-supplied file path inputs, an unauthenticated attacker can craft requests that traverse outside the intended directory boundary and target arbitrary files on the server. No authentication or user interaction is required, and the attack is executable remotely over the network with low complexity (Patchstack, Feedly).

Impact

Successful exploitation allows an unauthenticated attacker to delete arbitrary files from the WordPress installation, including core WordPress files, theme files, or configuration files. Deletion of critical files can cause the website to become completely non-functional, resulting in high availability impact with a changed scope (affecting systems beyond the vulnerable component itself). While the CVSS score reflects no direct confidentiality or integrity impact, the ability to delete files such as wp-config.php could indirectly expose sensitive database credentials or enable further compromise (Patchstack, Feedly).

Exploitability

There is no public proof-of-concept exploit code available, and no evidence of active in-the-wild exploitation has been observed as of the time of disclosure (Feedly). The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified. However, Patchstack classifies this as high priority, noting that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Scape theme (versions < 1.5.16) via tools like WPScan, Shodan, or by inspecting page source for theme references.
  2. Identify vulnerable endpoint: Locate the theme functionality that handles file path input without proper sanitization — typically a theme-specific AJAX action or admin-facing endpoint exposed to unauthenticated users.
  3. Craft path traversal payload: Construct a request with a directory traversal sequence (e.g., ../../) in the file path parameter to escape the intended directory and target a critical file (e.g., wp-config.php, .htaccess, or core WordPress files).
  4. Send malicious request: Submit the crafted HTTP request to the vulnerable endpoint without any authentication credentials.
  5. Achieve file deletion: The server processes the traversed path and deletes the targeted file, potentially breaking site functionality or enabling further exploitation (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP POST or GET requests to WordPress theme-related endpoints containing path traversal sequences (e.g., ../, ..%2F, ..%252F) in file path parameters; requests originating from unexpected or automated IP ranges.
  • Logs: WordPress or web server access logs showing requests to Scape theme AJAX handlers with encoded traversal strings; repeated 200 responses to file-manipulation endpoints from unauthenticated sessions.
  • File System: Unexpected absence of critical WordPress files such as wp-config.php, .htaccess, index.php, or core theme/plugin files; timestamps of file deletions correlating with suspicious log entries.
  • Application Behavior: WordPress site returning errors or becoming non-functional without administrator action; missing configuration files triggering database connection errors on the frontend.

Mitigation and workarounds

The vendor has released Scape theme version 1.5.16, which patches this vulnerability, and updating to this version or later is the recommended remediation (Patchstack). Patchstack has also issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until the theme is updated. As additional hardening measures, administrators should implement Web Application Firewall (WAF) rules to detect and block path traversal patterns, restrict network-level access to the WordPress admin interface, and monitor application logs for directory traversal attempts.

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability report covering March 16–22, 2026, highlighting it as part of broader WordPress ecosystem security monitoring (Wordfence). Patchstack, which coordinated the disclosure, classified it as high priority and emphasized the risk of mass-exploit campaigns targeting WordPress themes with this class of vulnerability (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management