Live2DWebCanvas [live-2d] < 1.9.12
unknown
[en] The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ClearFiles() function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files...
- Affected:
- up to 1.9.12
- Fixed in:
- 1.9.12
- Disclosed:
- Jan 31, 2025
CVE-2024-13767 on NVD →
Live2DWebCanvas <= 1.9.11 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ClearFiles() function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on t...
- CVSS:
- 8.1
- Affected:
- up to 1.9.11
- Fixed in:
- 1.9.12
- Disclosed:
- Jan 30, 2025
CVE-2024-13767 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database