WF-52c24f18-832b-4416-a148-a23e38b257e0-wp-dbmanager
WP-DBManager <= 2.79.1 - Directory Traversal Allowing Arbitrary File Deletion
highImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
8.7
CVSS Score
8.7
CVSS Score
high
Severity
2.79.2
Patched in
1919d
Time to patch
Description
The WP-DBManager plugin for WordPress is vulnerable to Directory Traversal allowing arbitrary file deletion in versions up to, and including, 2.79.1. This allows authenticated high-privilege attackers to delete arbitrary files, which can be used to reset a site and gain administrative access.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:HAttack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
None
Confidentiality
High
Integrity
High
Availability
Technical Details
Affected versions
<2.79.2PublishedOctober 22, 2018
Last updatedJanuary 22, 2024
Affected pluginwp-dbmanager
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.