mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-04 22:18:13 +02:00
966 B
966 B
CVE-2021-25020
Description
The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin
POC
Reference
- https://wpscan.com/vulnerability/67398332-b93e-46ae-8904-68419949a124
- https://wpscan.com/vulnerability/67398332-b93e-46ae-8904-68419949a124
Github
No PoCs found on GitHub currently.