Blog | G5 Cyber Security

Unpatched WordPress file deletion vulnerability could allow site takeover and code execution

Seven months ago, security experts discovered a critical file deletion vulnerability that affects all WordPress versions. The vulnerability could be exploited to complete takeover of the websites running the popular CMS and gain arbitrary code execution. The flaw resides in the WordPress Core, the code to trigger it was found in the wp-includes/post.php file: $meta[thumb is used to invoke the unlink() function without undergoing any sanitization. An arbitrary file deletion flaw occurs when it is possible to pass unsanitized input to a file deletion function.”]

Source: https://securityaffairs.co/wordpress/73944/hacking/wordpress-file-deletion-vulnerability.html

Exit mobile version