Lucene search

K
wpvulndbNhatnamWPVDB-ID:C043916A-92C9-4D02-8CCA-1A90E5382B7E
HistoryJul 27, 2022 - 12:00 a.m.

WordPress Team Members Showcase < 4.1.2 - Subscriber+ Arbitrary File Read and Deletion

2022-07-2700:00:00
nhatnam
wpscan.com
8
wordpress
team members
showcase
subscriber
arbitrary file read
arbitrary file deletion
path traversal
vector
authenticated users
server
content
deletion
poc
software

EPSS

0.001

Percentile

35.6%

The plugin contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user

PoC

https://example.com/wp-content/plugins/tlp-team/resources/download.php?file=../../../../test.txt

EPSS

0.001

Percentile

35.6%

Related for WPVDB-ID:C043916A-92C9-4D02-8CCA-1A90E5382B7E