MEDIUM
DesigningMedia
CVE published 2026-04-15
CVE-2025-15470
The Eleganzo theme for WordPress has a vulnerability allowing authenticated attackers with Subscriber-level access to delete arbitrary directories, including the WordPress root directory. This issue arises from insufficient path validation in the akd_required_plugin_callback function across all versions up to 1.2. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Site administrators and [truncated]