Junglewise Threat Intelligence

CVE-2026-57716: VideoWhisper Broadcast Live Video unauthenticated arbitrary file deletion

CVE-2026-57716 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Vendors: VideoWhisper.

Executive brief

The Broadcast Live Video plugin for WordPress, which provides live streaming and video integration features, contains a security flaw that allows unauthorized users to delete files from the web server. An attacker could use this to delete critical website files, potentially causing the site to crash or stop functioning entirely. This vulnerability can be exploited remotely without needing any login credentials.

Technical details

The VideoWhisper Broadcast Live Video plugin for WordPress (up to version 7.2.4) is vulnerable to arbitrary file deletion due to improper limitation of a pathname to a restricted directory (CWE-22). An unauthenticated remote attacker can exploit this path traversal vulnerability to delete arbitrary files on the server that the web service has permissions to modify. This can lead to a denial-of-service condition if core application or configuration files are targeted. The issue is resolved in version 7.2.5.

Affected products

  • VideoWhisper Broadcast Live Video <= 7.2.4

Timeline

  • 2026-06-26: other: Vulnerability reported by researcher dutafi
  • 2026-07-21: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD dataset

References