PluginPass <= 0.9.10 - Unauthenticated Arbitrary File Deletion
criticalThe PluginPass – WordPress PRO Plugin/Theme Licensing (Public Alpha) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 0.9.10. This makes it possible for unauthenticated attackers to delete arbitrary files on the se...
- CVSS:
- 9.1
- Affected:
- up to 0.9.10
- Fix:
- No patched version reported
- Disclosed:
- Mar 14, 2025