PT-2026-69946 · WordPress · Sucuri Security
CVE-2026-73033
·
Published
2026-08-10
·
Updated
2026-08-11
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Sucuri Security WordPress plugin versions prior to 2.7.4
Description
Authenticated administrators can delete arbitrary files by exploiting a path traversal issue in the
pageIntegritySubmission() function within src/integrity.lib.php. By providing directory traversal sequences in the sucuriscan integrity parameter, an attacker can manipulate the unsanitized file path concatenated with ABSPATH to move outside the WordPress installation directory. This allows the execution of the unlink() function on sensitive files, such as wp-config.php and .htaccess, which may lead to site outages or facilitate malicious reinstallation.Recommendations
Update Sucuri Security WordPress plugin to version 2.7.4 or later.
As a temporary mitigation, restrict access to the
pageIntegritySubmission() function in src/integrity.lib.php to prevent the use of the sucuriscan integrity parameter.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sucuri Security