WPCode Lite < 2.0.9 - Arbitrary Log File Deletion via CSRF
CVE-2023-1624

6.5MEDIUM

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
24 April 2023

Summary

The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be deleted is inside the expected folder. This could allow attackers to make users with the wpcode_activate_snippets capability delete arbitrary log files on the server, including outside of the blog folders

Affected Version(s)

WPCode 0 < 2.0.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Erwan LR (WPScan)
WPScan
.