Lucene search

K
wpvulndbWpvulndbWPVDB-ID:DB395FAB-D66A-4E52-8668-689E614328C7
HistoryJan 03, 2024 - 12:00 a.m.

JVM rich text icons < 1.2.7 - Subscriber+ Arbitrary File Deletion

2024-01-0300:00:00
wpscan.com
6
jvm
rich text icons
wordpress
directory traversal
authenticated attackers
subscriber access

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

9.0%

Description The JVM Gutenberg Rich Text Icons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the ‘file’ parameter. This makes it possible for authenticated attackers, with subscriber access and above, to delete arbitrary files.

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

9.0%

Related for WPVDB-ID:DB395FAB-D66A-4E52-8668-689E614328C7