Junglewise Threat Intelligence

CVE-2025-69139: AivahThemes Car Zone arbitrary file deletion

CVE-2025-69139 · Severity: high · CVSS 8.6 · Published 2026-06-17

Executive brief

The Car Zone theme for WordPress is vulnerable to a security flaw that allows unauthorized individuals to delete files from the web server. This could lead to a complete website failure or the removal of critical configuration files, potentially causing significant downtime and operational disruption. As there is currently no official patch from the developer, site owners should consider alternative security mitigations or switching themes.

Technical details

An arbitrary file deletion vulnerability exists in the Car Zone theme for WordPress through version 3.7. The flaw is rooted in improper limitation of a pathname to a restricted directory (CWE-22), commonly known as path traversal. An unauthenticated remote attacker can exploit this by sending specially crafted requests to the server, allowing them to delete arbitrary files that the web server process has permissions to modify. This can result in a denial-of-service condition by deleting core WordPress or theme files. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • AivahThemes Car Zone <= 3.7

Timeline

  • 2025-10-28: other: Vulnerability reported by researcher
  • 2026-05-26: advisory: Patchstack published advisory details
  • 2026-06-17: disclosed: CVE published to NVD

References