Lucene search

K
wpvulndbWpvulndbWPVDB-ID:66D04DF5-FE00-436D-8135-47ECFD52A6A7
HistoryJan 05, 2024 - 12:00 a.m.

Uncode Core < 2.8.9 - Authenticated (Subscriber+) Arbitrary File Deletion

2024-01-0500:00:00
wpscan.com
8
uncode core
2.8.9
authenticated
arbitrary file deletion
wordpress

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Description The uncode-core plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.8.8. This makes it possible for authenticated attackers with subscriber level access or higher to delete arbitrary files on the site.

CPENameOperatorVersion
eq2.8.9

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Related for WPVDB-ID:66D04DF5-FE00-436D-8135-47ECFD52A6A7