PT-2025-33463 · WordPress · Icons Factory

Johska

·

Published

2025-08-15

·

Updated

2025-08-15

·

CVE-2025-7778

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Icons Factory plugin for WordPress versions up to and including 1.6.12
Description: The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within the delete files() function. This allows unauthenticated attackers to delete arbitrary files on the server, potentially leading to remote code execution if critical files, such as wp-config.php, are deleted.
Recommendations: Update the Icons Factory plugin to a version newer than 1.6.12.

Fix

RCE

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-7778

Affected Products

Icons Factory