Arbitrary file write and delete via path traversal
Published Aug 19, 2026 · Updated Aug 19, 2026
Arbitrary file upload and deletion in CMSJunkie J-BusinessDirectory before 6.2.3 allows remote attackers to write or remove files. The upload and remove handlers accept a client-controlled _path_type that can select the component's site or administrator trees, fail to confine paths to an intended directory, and rely on a weak extension check for uploaded content. No authentication or user interaction is required per the published CVSS; reachable requests can plant executable files or delete existing component files, leading to code execution or service interruption within those trees.
Summary
What happened
Arbitrary file upload and deletion in CMSJunkie J-BusinessDirectory before 6.2.3 allows remote attackers to write or remove files. The upload and remove handlers accept a client-controlled _path_type that can select the component's site or administrator trees, fail to confine paths to an intended directory, and rely on a weak extension check for uploaded content. No authentication or user interaction is required per the published CVSS; reachable requests can plant executable files or delete existing component files, leading to code execution or service interruption within those trees.
The record
- CVE
- CVE-2026-75949
- Published
- Aug 19, 2026
- Updated
- Aug 19, 2026
- Vendor
- CMSJunkie - WordPress Business Directory Plugins
- Product
- J-BusinessDirectory
- Classifications
- CWE-434, T1190
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 19, 2026CVE publishedPublication date reported by the CVE source.
- Aug 19, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=1.0.0-6.2.2
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo