Simple File List Plugin <= 3.2.4 - Authenticated Arbitrary File Delete



Description
Arbitrary File Delete exist in Simple File List Plugin v 3.2.4 or below

Authentication Required: Yes

Affects Plugin

fixed in version 3.2.5

References

URL https://docs.google.com/document/d/11KLjuMaHLjPBf2R-Af1R01JNebD5mLRDBnCadmNmC_M/edit?usp=sharing
URL https://plugins.trac.wordpress.org/changeset/2093272/simple-file-list

Classification

Type TRAVERSAL
OWASP Top 10 A1: Injection
CWE CWE-22

Miscellaneous

Original Researcher Admavidhya N
Submitter Admavidhya N
Views 3453
Verified No
WPVDB ID 9288

Timeline

Publicly Published 2019-05-23 (4 months ago)
Added 2019-05-27 (4 months ago)
Last Updated 2019-05-27 (4 months ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin