Vulnerabilities and security researches forword-count-and-social-shares word-count-and-social-shares
Direction: ascendingJul 17, 2026
Word Count and Social Shares # CVE-2026-11563
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 14, 2026
- Research Description
- The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files on the server, which can lead to a full site takeover (e.g. by deleting wp-config.php).
- Affected versions
-
max 1.0.
- Status
-
vulnerable