Goza Nonprofit Charity WordPress Theme Arbitrary File Deletion Vulnerability
Vulnerability
A vulnerability allowing arbitrary file deletion has been identified in the Goza - Nonprofit Charity WordPress Theme, all versions through 3.2.2. This issue arises from inadequate file path validation in the alone_import_pack_restore_data() function, enabling unauthenticated attackers to delete arbitrary files on the server. Such deletion can easily result in remote code execution if critical files, like wp-config.php, are removed.
Impact
Exploitation of this vulnerability could lead to unauthorized deletion of files on the server, with the potential for remote code execution if a sensitive file is deleted.
Remediation
Users are advised to update to version 3.2.3 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
