CVE-2026-104722: Webilia Listdom: Ai-Powered Business Directory With Classifieds Ads Listings

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the LSD_Menus_IX_CSV::import function in all versions up to, and including, 6.1.2 This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Affected products

  • Webilia Listdom: Ai-Powered Business Directory With Classifieds Ads Listings: up to and including 6.1.2

Published 2026-10-10. Last modified 2026-10-10.