Real3D Flipbook <= 2.8 - Unauthenticated Arbitrary File or Directory Delete

2016-07-02 00:00
Mukarram Khalid

Strategic Overview

Status
Patched in 2.9
Affected PluginReal3D Flipbook
Affected Version< 2.9
CVSS10.0Critical
CVEN/A
View all Real3D Flipbook vulnerabilities

Vulnerability Overview

The Real3D Flipbook plugin for WordPress is vulnerable to Unauthenticated File or Directory Delete in versions up to, and including, 2.8. This is due to missing privilege checks. This makes it possible for unauthenticated attackers to delete arbitrary files or folders on the site.

Technical Analysis

REMEDIATION: Update to version 2.9, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C