WordPress Plugin Vulnerabilities

HyperComments <= 1.2.2 - Unauthenticated Arbitrary File Deletion

Description

The plugin does not validate and sanitise user input which is being concatenated to create a file path, passed to unlink(), which leads to an arbitrary file deletion issue.

For more details about this issue, please see the reference.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
FILE DELETION
CWE

Miscellaneous

Original Researcher
Lenon Leite
Submitter
Lenon Leite
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2020-10-07 (about 5 years ago)
Added
2020-10-07 (about 5 years ago)
Last Updated
2020-10-08 (about 5 years ago)

Other