SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-11563

CRITICAL · CVSS 9.6 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The Word Count and Social Shares plugin for WordPress is vulnerable due to inadequate validation of user-supplied file paths and a lack of proper authorization and CSRF checks, enabling any authenticated user, including those with minimal privileges like Subscribers, to delete critical files on the server. This vulnerability poses a severe risk, as it could lead to a complete site takeover by allowing the deletion of essential files such as wp-config.php. WordPress site administrators and security teams should prioritize patching or disabling this plugin to mitigate the risk of exploitation.

CVE
CVE-2026-11563
Severity
CRITICAL
CVSS
9.6
EPSS
0.17%
WordPress

Original NVD Description

The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files on the server, which can lead to a full site takeover (e.g. by deleting wp-config.php).