CVE-2026-73033: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Sucuri sucuri-wordpress-plugin
Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integrity.lib.php that allows authenticated administrators to delete arbitrary files by supplying directory traversal sequences in the sucuriscan_integrity parameter. Attackers can manipulate the unsanitized file path concatenated with ABSPATH to traverse outside the WordPress installation directory and invoke unlink() on sensitive files such as wp-config.php and .htaccess, causing site outage or enabling malicious reinstallation.
AI Analysis
Technical Summary
CVE-2026-73033 is a path traversal vulnerability in the Sucuri Security WordPress plugin versions up to 2.7.3. The flaw exists in the pageIntegritySubmission() method within src/integrity.lib.php, where the sucuriscan_integrity parameter is not properly sanitized. Authenticated administrators can supply directory traversal sequences that manipulate the file path concatenated with ABSPATH, allowing unlink() to delete arbitrary files outside the WordPress installation directory. This can lead to site outages or enable attackers to reinstall malicious content.
Potential Impact
An authenticated administrator can exploit this vulnerability to delete arbitrary files on the server, including critical configuration files such as wp-config.php and .htaccess. This can result in site downtime or enable attackers to compromise the site by reinstalling malicious code. The CVSS 4.0 score is 7.0 (high severity), reflecting the potential for significant impact when exploited.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict administrator access to trusted users only and monitor for suspicious activity related to file deletions via the plugin. Avoid using versions up to 2.7.3 in production environments if possible.
CVE-2026-73033: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Sucuri sucuri-wordpress-plugin
Description
Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integrity.lib.php that allows authenticated administrators to delete arbitrary files by supplying directory traversal sequences in the sucuriscan_integrity parameter. Attackers can manipulate the unsanitized file path concatenated with ABSPATH to traverse outside the WordPress installation directory and invoke unlink() on sensitive files such as wp-config.php and .htaccess, causing site outage or enabling malicious reinstallation.
CVSS v4.0
Score 7.0high
Affected software
Sucuri
sucuri-wordpress-plugin
pkg:github/sucuri-wordpress-pluginRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-73033 is a path traversal vulnerability in the Sucuri Security WordPress plugin versions up to 2.7.3. The flaw exists in the pageIntegritySubmission() method within src/integrity.lib.php, where the sucuriscan_integrity parameter is not properly sanitized. Authenticated administrators can supply directory traversal sequences that manipulate the file path concatenated with ABSPATH, allowing unlink() to delete arbitrary files outside the WordPress installation directory. This can lead to site outages or enable attackers to reinstall malicious content.
Potential Impact
An authenticated administrator can exploit this vulnerability to delete arbitrary files on the server, including critical configuration files such as wp-config.php and .htaccess. This can result in site downtime or enable attackers to compromise the site by reinstalling malicious code. The CVSS 4.0 score is 7.0 (high severity), reflecting the potential for significant impact when exploited.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict administrator access to trusted users only and monitor for suspicious activity related to file deletions via the plugin. Avoid using versions up to 2.7.3 in production environments if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-10T18:48:59.022Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a7a3406bf8831d5397b0364
Added to database: 08/10/2026, 20:26:46 UTC
Last enriched: 08/10/2026, 20:41:08 UTC
Last updated: 09/25/2026, 01:47:44 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.