WordPress Vulnerabilities
WordPress <= 4.9.6 - Authenticated Arbitrary File Deletion
Description
This can lead to code execution if the wp-config.php file is deleted, forcing WordPress to start the installation process.
Can be exploited by any user who is able to edit uploaded media.
Affects WordPress
References
CVE
URL
Miscellaneous
Submitter
Ryan
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2018-06-27 (about 8 years ago)
Added
2018-06-27 (about 8 years ago)
Last Updated
2020-09-22 (about 5 years ago)