Envolve Plugin for WordPress Arbitrary File Deletion Vulnerability
Vulnerability
A vulnerability allowing arbitrary file deletion has been identified in the Envolve Plugin for WordPress, affecting all versions through 1.0. The issue arises in the 'zetra_deleteLanguageFile' and 'zetra_deleteFontsFile' functions, where the plugin fails to properly validate files or their paths before deletion. This flaw enables unauthenticated attackers to delete language files from the server.
Impact
Exploitation of this vulnerability allows for unauthorized deletion of language files, which could disrupt the functionality of the WordPress site or the plugin itself.
Remediation
Users are advised to update the Envolve Plugin to version 1.1.0 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
