Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5192
HistorySep 29, 2017 - 2:36 a.m.

Directory Traversal

2017-09-2902:36:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

EPSS

0.005

Percentile

76.0%

Wordpress is vulnerable to directory traversal attacks. The library does not validate file names before attempting to unzip them, allowing a malicious user to pass a malformed path to traverse the application’s directory.