PT-2026-69946 · WordPress · Sucuri Security

CVE-2026-73033

·

Published

2026-08-10

·

Updated

2026-08-11

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Sucuri Security WordPress plugin versions prior to 2.7.4
Description Authenticated administrators can delete arbitrary files by exploiting a path traversal issue in the pageIntegritySubmission() function within src/integrity.lib.php. By providing directory traversal sequences in the sucuriscan integrity parameter, an attacker can manipulate the unsanitized file path concatenated with ABSPATH to move outside the WordPress installation directory. This allows the execution of the unlink() function on sensitive files, such as wp-config.php and .htaccess, which may lead to site outages or facilitate malicious reinstallation.
Recommendations Update Sucuri Security WordPress plugin to version 2.7.4 or later. As a temporary mitigation, restrict access to the pageIntegritySubmission() function in src/integrity.lib.php to prevent the use of the sucuriscan integrity parameter.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73033

Affected Products

Sucuri Security