WordPress Plugin Vulnerabilities
Import users from CSV with meta < 1.14.2.2 - CSRF leading to attachment deletion & Path Traversal
Description
CSRF leading to attachment deletion via the acui_delete_attachment() AJAX function.
Affects Plugins
References
Miscellaneous
Verified
No
WPVDB ID
Timeline
Publicly Published
2019-06-22 (about 6 years ago)
Added
2019-06-26 (about 6 years ago)
Last Updated
2020-09-22 (about 5 years ago)