← WordPress Vulnerabilities
WordPress security by component

Eleganzo

Eleganzo is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Apr 15, 2026; the highest CVE/CNA score is 6.5.

Theme slug: eleganzo

CVE-2025-15470: Eleganzo: Arbitrary file deletion

Eleganzo is affected by arbitrary file deletion. Exploitation requires at least subscriber-level access. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 1.2.

PublishedApr 15, 2026
Known safe version> 1.2
Safe version
Apr 15, 2026 CVE-2025-15470
Eleganzo: Arbitrary file deletion
Eleganzo is affected by arbitrary file deletion. Exploitation requires at least subscriber-level access. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is <= 1.2.
> 1.2
CVE6.5
NVDPending