Icons Factory <= 1.6.12 - Missing Authorization to Unauthenticated Arbitrary File Deletion via delete_files() Function
criticalThe Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within the delete_files() function in all versions up to, and including, 1.6.12. This makes it possible for unauthenticated attackers to to delete arbitrary files on the server,...
- CVSS:
- 9.8
- Affected:
- up to 1.6.12
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2025