


Perceptive Security
SOC/SIEM Consultancy

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows…
Published:
26 May 2026 at 22:00:00
Alert date:
27 May 2026 at 15:06:57
Source:
nvd.nist.gov
Web Technologies
Path traversal vulnerability in Saleswonder Team WebinarIgnition plugin allows attackers to traverse directories beyond restricted paths. The vulnerability affects WebinarIgnition versions up to 4.08.253. This improper limitation of pathname to restricted directory can lead to unauthorized file access. The issue is tracked as CVE-2026-42757 and has been assigned high criticality. A patch is available in version 4.08.253 and later. The vulnerability specifically allows path traversal attacks that can bypass directory restrictions.
Technical details
Mitigation steps:
Affected products:
WebinarIgnition
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42757
https://patchstack.com/database/Wordpress/Plugin/webinar-ignition/vulnerability/wordpress-webinarignition-plugin-4-08-253-arbitrary-file-deletion-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
