CVE-2024-12885 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a c…
Medium CVSS: 6.5

CVE-2024-12885

The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory in all versions up to, and including, 10.4.66. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary folders on the server and all their content.
Vendor
-
Product
-
CWE
CWE-22
Yayın Tarihi
2025-01-25 08:15:08
Güncelleme
2026-04-15 00:35:42
Source Identifier
security@wordfence.com
KEV Date Added
-

Kategoriler

Referanslar