cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forword-count-and-social-shares word-count-and-social-shares

Direction: ascending
Jul 17, 2026

Word Count and Social Shares # CVE-2026-11563

CVE, Research URL

CVE-2026-11563

Date
Jul 14, 2026
Research Description
The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files on the server, which can lead to a full site takeover (e.g. by deleting wp-config.php).
Affected versions
max 1.0.
Status
vulnerable