The plugin does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin
As admin, put the following payload in the "Fonts Cache Directory" setting of the plugin: ../wp-includes, tick the "Remove settings at Uninstall" setting and uninstall the plugin to delete the wp-includes folder
José Aguilera
José Aguilera
Yes
2021-12-01 (about 1 years ago)
2021-12-01 (about 1 years ago)
2022-04-09 (about 1 years ago)