Executive brief
WebinarIgnition, a WordPress plugin used for managing webinars, contains a critical security flaw that allows attackers to access or delete files outside of the intended directory. This could lead to the deletion of critical website files, potentially causing a total site outage or allowing an attacker to compromise the server. Organizations using this plugin should update to version 4.08.253 or later immediately to protect their data and operations.
Technical details
A path traversal vulnerability (CWE-22) exists in the Saleswonder Team: Tobias WebinarIgnition plugin for WordPress. The flaw stems from improper limitation of pathnames to a restricted directory, specifically allowing arbitrary file deletion as indicated by the vendor's advisory title. An attacker with low-level authentication (PR:L) can exploit this over the network to manipulate file paths, potentially leading to a full system compromise or denial of service by deleting critical configuration files. The vulnerability is addressed in version 4.08.253.
Affected products
- Saleswonder Team: Tobias WebinarIgnition < 4.08.253
Timeline
- 2026-05-27: advisory: NVD and Patchstack published the vulnerability details.
- 2026-05-27: disclosed