PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104722 webilia CVE debrief

CVE-2026-104722 is a vulnerability in the Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress, allowing authenticated administrators to delete arbitrary files due to insufficient file path validation. This vulnerability has a medium severity and can lead to potential remote code execution when sensitive files are deleted. Defenders should verify their version, review file permissions, and implement compensating controls to prevent exploitation. The vulnerability affects all versions up to, and including, 6.1.2 of the Listdom plugin.

Vendor
webilia
Product
Listdom: AI-powered Business Directory with Classifieds Ads Listings
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Administrators of WordPress installations with the Listdom plugin should assess their exposure and take action to prevent exploitation. This includes verifying their version of the plugin, reviewing file permissions and access controls, and implementing compensating controls as needed. Additionally, operators of affected platforms and vulnerability management teams should review the vulnerability and take action to mitigate it.

Why it matters

CVE-2026-104722 is a medium-severity vulnerability in the Listdom plugin for WordPress, allowing authenticated administrators to delete arbitrary files. Defenders should verify their version, review file permissions, and implement compensating controls to prevent exploitation.

  • Potential for remote code execution when sensitive files are deleted
  • Ability for attackers to delete arbitrary files on the server
  • Need for verification of file permissions and access controls
  • Requirement for monitoring and compensating controls

Technical summary

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the LSD_Menus_IX_CSV::import function in all versions up to, and including, 6.1.2. This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The vulnerability has a CVSS score of 4.9 and is considered medium severity.

Defensive priority

Administrators of WordPress installations with the Listdom plugin should verify their version and update to a patched version if available, and review file permissions and access controls.

Recommended defensive actions

  • Verify the version of the Listdom plugin and update to a patched version if available
  • Review file permissions and access controls to prevent arbitrary file deletion
  • Monitor for suspicious activity and implement compensating controls as needed
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability is caused by insufficient file path validation in the LSD_Menus_IX_CSV::import function. The source item and CVE record provide evidence of the vulnerability, but defenders should verify their specific deployments and review file permissions to ensure they are not exposed. The evidence is limited to publicly available information and may not reflect the full scope of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104722 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104722

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104722 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104722

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.2 - Authenticated (A

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104722.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/listdom/tags/6.1.2/app/includes/menus/ix/csv.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/listdom/tags/6.1.2/app/includes/file.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://wordpress.org/plugins/listdom/

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/changeset/3726849/listdom/trunk/app/includes/menus/ix/csv.php

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.