
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31913 is a Path Traversal (Arbitrary File Deletion) vulnerability in the Whitebox-Studio Scape WordPress theme that allows unauthenticated remote attackers to delete arbitrary files on the server. It affects all Scape theme versions prior to 1.5.16 and was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on February 5, 2026, with public disclosure on March 20–25, 2026. The vulnerability carries a CVSS v3.1 base score of 8.6 (High) (Patchstack, Feedly).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and manifests as an arbitrary file deletion capability within the Scape WordPress theme. Due to insufficient validation of user-supplied file path inputs, an unauthenticated attacker can craft requests that traverse outside the intended directory boundary and target arbitrary files on the server. No authentication or user interaction is required, and the attack is executable remotely over the network with low complexity (Patchstack, Feedly).
Successful exploitation allows an unauthenticated attacker to delete arbitrary files from the WordPress installation, including core WordPress files, theme files, or configuration files. Deletion of critical files can cause the website to become completely non-functional, resulting in high availability impact with a changed scope (affecting systems beyond the vulnerable component itself). While the CVSS score reflects no direct confidentiality or integrity impact, the ability to delete files such as wp-config.php could indirectly expose sensitive database credentials or enable further compromise (Patchstack, Feedly).
There is no public proof-of-concept exploit code available, and no evidence of active in-the-wild exploitation has been observed as of the time of disclosure (Feedly). The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified. However, Patchstack classifies this as high priority, noting that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
../../) in the file path parameter to escape the intended directory and target a critical file (e.g., wp-config.php, .htaccess, or core WordPress files).../, ..%2F, ..%252F) in file path parameters; requests originating from unexpected or automated IP ranges.wp-config.php, .htaccess, index.php, or core theme/plugin files; timestamps of file deletions correlating with suspicious log entries.The vendor has released Scape theme version 1.5.16, which patches this vulnerability, and updating to this version or later is the recommended remediation (Patchstack). Patchstack has also issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until the theme is updated. As additional hardening measures, administrators should implement Web Application Firewall (WAF) rules to detect and block path traversal patterns, restrict network-level access to the WordPress admin interface, and monitor application logs for directory traversal attempts.
Wordfence included this vulnerability in their weekly WordPress vulnerability report covering March 16–22, 2026, highlighting it as part of broader WordPress ecosystem security monitoring (Wordfence). Patchstack, which coordinated the disclosure, classified it as high priority and emphasized the risk of mass-exploit campaigns targeting WordPress themes with this class of vulnerability (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."