Skip to content
CVE-2026-57331 - Exploits & Severity

CVE-2026-57331 - Exploits & Severity

Feedly June 29, 2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

Performer Arbitrary File Deletion in Paid Videochat Turnkey Site versions 7.4.8 and earlier allows authenticated users with performer privileges to delete arbitrary files.

An authenticated performer can delete arbitrary files on the system, potentially causing data loss, service disruption, or enabling further system compromise.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Update Paid Videochat Turnkey Site to a version later than 7.4.8. Restrict performer account permissions to the minimum necessary for legitimate operations. Monitor file system activity for unauthorized deletion operations. Review and audit performer account access logs.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

NVD published the first details for CVE-2026-57331

Feedly found the first article mentioning CVE-2026-57331 . See article

A CVSS base score of 9.9 has been assigned.

GitHub Advisories released a security advisory .

[GHSA-752c-x542-h98f] Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versio

CVE-2026-57331 Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.

CVE-2026-57331 | videowhisper Paid Videochat Turnkey Site Plugin up to 7.4.8 on WordPress path traversal

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

CWE Weaknesses (1)

Platforms (1)

Vulnerabilities (1)