Executive brief
ShopBuilder Pro is a WordPress plugin that provides e-commerce page building features for WooCommerce stores. This vulnerability allows unauthenticated attackers to delete arbitrary files from affected websites, potentially destroying critical site data and causing complete service outages.
Technical details
This is an unauthenticated arbitrary file deletion vulnerability in ShopBuilder Pro – Elementor WooCommerce Builder Addons plugin versions 2.2.0 and below. The vulnerability stems from broken access control (OWASP A1), allowing attackers without authentication to issue file deletion requests. The attack is network-reachable and requires no user interaction or authentication. Successful exploitation enables attackers to delete critical website files, causing immediate denial of service and potential data loss. No official patch was available as of the advisory publication date; Patchstack provided a mitigation rule to block exploitation attempts.
Affected products
- ShopBuilder ShopBuilder Pro <= 2.2.0
Timeline
- 2026-08-24: disclosed
- 2026-07-09: reported
- other: No official patch available as of advisory date