LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2021-47979

Published
CVSS8.8
Severityhigh
WeaknessCWE-22
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers can send POST requests to admin-ajax.php with crafted file_name and folder_name parameters to delete arbitrary files from the WordPress installation directory.

References

← Back to the CVE Tracker

Our coverage of CVE-2021-47979

No stories yet. This page updates automatically when we publish reporting that references CVE-2021-47979.