CVE-2025-8575: LWS Cleaner <= 2.4.1.3 - Authenticated (Administrator+) Arbitrary File Deletion via 'lws_cl_delete_file'
The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'lwscldeletefile' function in all versions up to, and including, 2.4.1.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8575?
CVE-2025-8575 is classified as a critical severity vulnerability due to its ability to allow arbitrary file deletion.
How do I fix CVE-2025-8575?
To fix CVE-2025-8575, update the LWS Cleaner plugin to version 2.4.1.4 or later.
Who is affected by CVE-2025-8575?
CVE-2025-8575 affects all versions of the LWS Cleaner plugin up to and including version 2.4.1.3.
What type of attack does CVE-2025-8575 enable?
CVE-2025-8575 enables authenticated attackers with Administrator-level access to delete arbitrary files.
Where is CVE-2025-8575 found?
CVE-2025-8575 is found in the LWS Cleaner plugin for WordPress, specifically in the 'lws_cl_delete_file' function.