PatchSiren cyber security CVE debrief
CVE-2026-104722 webilia CVE debrief
CVE-2026-104722 is a vulnerability in the Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress, allowing authenticated administrators to delete arbitrary files due to insufficient file path validation. This vulnerability has a medium severity and can lead to potential remote code execution when sensitive files are deleted. Defenders should verify their version, review file permissions, and implement compensating controls to prevent exploitation. The vulnerability affects all versions up to, and including, 6.1.2 of the Listdom plugin.
- Vendor
- webilia
- Product
- Listdom: AI-powered Business Directory with Classifieds Ads Listings
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Administrators of WordPress installations with the Listdom plugin should assess their exposure and take action to prevent exploitation. This includes verifying their version of the plugin, reviewing file permissions and access controls, and implementing compensating controls as needed. Additionally, operators of affected platforms and vulnerability management teams should review the vulnerability and take action to mitigate it.
Why it matters
CVE-2026-104722 is a medium-severity vulnerability in the Listdom plugin for WordPress, allowing authenticated administrators to delete arbitrary files. Defenders should verify their version, review file permissions, and implement compensating controls to prevent exploitation.
- Potential for remote code execution when sensitive files are deleted
- Ability for attackers to delete arbitrary files on the server
- Need for verification of file permissions and access controls
- Requirement for monitoring and compensating controls
Technical summary
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the LSD_Menus_IX_CSV::import function in all versions up to, and including, 6.1.2. This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The vulnerability has a CVSS score of 4.9 and is considered medium severity.
Defensive priority
Administrators of WordPress installations with the Listdom plugin should verify their version and update to a patched version if available, and review file permissions and access controls.
Recommended defensive actions
- Verify the version of the Listdom plugin and update to a patched version if available
- Review file permissions and access controls to prevent arbitrary file deletion
- Monitor for suspicious activity and implement compensating controls as needed
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability is caused by insufficient file path validation in the LSD_Menus_IX_CSV::import function. The source item and CVE record provide evidence of the vulnerability, but defenders should verify their specific deployments and review file permissions to ensure they are not exposed. The evidence is limited to publicly available information and may not reflect the full scope of the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104722 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104722
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104722 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104722
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.2 - Authenticated (A
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104722.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/listdom/tags/6.1.2/app/includes/menus/ix/csv.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/listdom/tags/6.1.2/app/includes/file.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://wordpress.org/plugins/listdom/
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3726849/listdom/trunk/app/includes/menus/ix/csv.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.