Real3D Flipbook <= 2.8 - Unauthenticated Arbitrary File or Directory Delete
2016-07-02 00:00
Mukarram KhalidStrategic Overview
Vulnerability Overview
The Real3D Flipbook plugin for WordPress is vulnerable to Unauthenticated File or Directory Delete in versions up to, and including, 2.8. This is due to missing privilege checks. This makes it possible for unauthenticated attackers to delete arbitrary files or folders on the site.
Technical Analysis
REMEDIATION: Update to version 2.9, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C