Image Slider < 1.1.90 - Arbitrary File Deletion

2016-12-23 00:00
dwxsupport

Strategic Overview

Status
Patched in 1.1.90
Affected PluginImage Slider
Affected Version< 1.1.90
CVSS8.1High
CVEN/A
View all Image Slider vulnerabilities

Vulnerability Overview

The Image Slider plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.1.89. This is due to allowing any user to edit 'Sliders'. This makes it possible for authenticated attackers with account level to create/edit posts to delete any files found in the plugin.

Technical Analysis

REMEDIATION: Update to version 1.1.90, or a newer patched version --- IDENTIFIER: CWE-73 (External Control of File Name or Path) The product allows user input to control or influence paths or file names that are used in filesystem operations.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C