vulnerable to Directory Traversal – critical threat
-
“All In One Favicon plugin for WordPress is vulnerable to Directory Traversal via the ‘aioFaviconUpdateSettings’ function in versions up to, and including, 4.7. This allows authenticated attackers with administator-level permissions to delete arbitrary files on the site.”
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/all-in-one-favicon/all-in-one-favicon-47-authenticatedadmin-directory-traversal
Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
- The topic ‘vulnerable to Directory Traversal – critical threat’ is closed to new replies.