Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-36836

Опубликовано: 16 окт. 2024
Источник: nvd
CVSS3: 8.8
CVSS3: 8.1
EPSS Средний

Описание

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wpfastestcache:wp_fastest_cache:*:*:*:*:*:wordpress:*:*
Версия до 0.9.0.3 (исключая)

EPSS

Процентиль: 96%
0.29174
Средний

8.8 High

CVSS3

8.1 High

CVSS3

Дефекты

CWE-352
CWE-22

Связанные уязвимости

CVSS3: 8.8
github
больше 1 года назад

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.

EPSS

Процентиль: 96%
0.29174
Средний

8.8 High

CVSS3

8.1 High

CVSS3

Дефекты

CWE-352
CWE-22