CVE-2026-73033

Source
https://cve.org/CVERecord?id=CVE-2026-73033
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73033.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73033
Published
2026-08-10T20:15:30.945Z
Modified
2026-08-13T03:51:52.717722483Z
Severity
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php
Details

Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integrity.lib.php that allows authenticated administrators to delete arbitrary files by supplying directory traversal sequences in the sucuriscan_integrity parameter. Attackers can manipulate the unsanitized file path concatenated with ABSPATH to traverse outside the WordPress installation directory and invoke unlink() on sensitive files such as wp-config.php and .htaccess, causing site outage or enabling malicious reinstallation.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73033.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/sucuri/sucuri-wordpress-plugin

Affected ranges

Type
GIT
Repo
https://github.com/sucuri/sucuri-wordpress-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.7.3"
        },
        {
            "fixed": "2.7.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

1.*
1.8.26
1.8.27
1.8.28
1.8.29
1.8.30
1.8.31
1.8.32
1.8.33
1.8.34
1.8.35
1.8.36
1.8.37
1.8.38
1.8.39
1.8.40
1.8.41
1.8.42
1.8.43
1.8.44
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.*
2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
2.7.1
2.7.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73033.json"