Junglewise Threat Intelligence

CVE-2026-6070: cmsjunkie WP-BusinessDirectory arbitrary file deletion via path traversal

CVE-2026-6070 · Severity: critical · CVSS 9.1 · Published 2026-07-01

Vendors: Cmsjunkie.

Executive brief

The WP-BusinessDirectory plugin for WordPress, used to create business listings, contains a security flaw that allows anyone to delete files from the website's server without logging in. An attacker could use this to delete critical configuration files, potentially taking the website offline or resetting it to a state where they can take full control. This poses a significant risk to site availability and data integrity.

Technical details

The vulnerability exists in the JBusinessDirectoryControllerUpload::remove() method due to a lack of sanitization on the _filename parameter and insufficient path validation in the makePathFile() helper function. The task=upload.remove endpoint is accessible to unauthenticated users via the plugin's frontend routing. By supplying path traversal sequences (../) in the _filename parameter and setting _path_type=2, an attacker can bypass the intended directory restrictions. This allows the execution of the PHP unlink() function on arbitrary files accessible to the web server process, such as wp-config.php. The issue affects all versions up to and including 4.0.1.

Affected products

  • cmsjunkie WP-BusinessDirectory up to and including 4.0.1

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory

References