BuddyPress Xprofile Custom Fields Type <= 2.6.3 - Arbitrary File Deletion
mediumThe BuddyPress Xprofile Custom Fields Type plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.6.3. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with low-level privileges and above to arbitrarily dele...
- CVSS:
- 6.5
- Affected:
- up to 2.6.3
- Fix:
- No patched version reported
- Disclosed:
- Jan 4, 2018