The Export All URLs WordPress plugin before 4.4 does not...
Moderate severity
Unreviewed
Published
Aug 29, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Aug 29, 2022
Published to the GitHub Advisory Database
Aug 29, 2022
Last updated
Jan 30, 2023
The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server
References