Executive brief
The Paid Videochat Turnkey Site plugin for WordPress, which provides infrastructure for live webcam and video chat services, contains a critical security flaw. An attacker with 'performer' level access can delete arbitrary files from the web server. This could lead to a complete site failure if core system files are removed, or allow an attacker to bypass security controls by deleting configuration files.
Technical details
An arbitrary file deletion vulnerability exists in the VideoWhisper Paid Videochat Turnkey Site plugin for WordPress (versions 7.4.8 and below) due to improper limitation of a pathname to a restricted directory (CWE-22). The flaw allows an authenticated user with 'Performer' privileges to send specially crafted requests to delete files outside of the intended directory. This is achieved via path traversal sequences. Successful exploitation can lead to a total loss of availability if critical system or configuration files are deleted, and may facilitate further compromise. The issue is resolved in version 7.4.9.
Affected products
- VideoWhisper Paid Videochat Turnkey Site <= 7.4.8
Timeline
- 2026-04-17: other: Vulnerability reported by researcher endy
- 2026-06-29: disclosed: Vulnerability published by Patchstack and NVD
- 2026-06-29: patched: Fixed in version 7.4.9