Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site versions 7.4.8 and earlier allows authenticated users with performer privileges to delete arbitrary files.
An authenticated performer can delete arbitrary files on the system, potentially causing data loss, service disruption, or enabling further system compromise.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Update Paid Videochat Turnkey Site to a version later than 7.4.8. Restrict performer account permissions to the minimum necessary for legitimate operations. Monitor file system activity for unauthorized deletion operations. Review and audit performer account access logs.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
NVD published the first details for CVE-2026-57331
Feedly found the first article mentioning CVE-2026-57331 . See article
A CVSS base score of 9.9 has been assigned.
GitHub Advisories released a security advisory .
[GHSA-752c-x542-h98f] Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versio
CVE-2026-57331 Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
CVE-2026-57331 | videowhisper Paid Videochat Turnkey Site Plugin up to 7.4.8 on WordPress path traversal
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
