Ovatheme Movie Booking Path Traversal Vulnerability Allowing Arbitrary File Deletion
Vulnerability
A path traversal vulnerability has been identified in the Ovatheme Movie Booking WordPress plugin, specifically in versions through 1.1.5. This vulnerability allows for improper limitation of a pathname to a restricted directory, enabling arbitrary file deletion. Exploiting this issue could lead to the deletion of critical files from a website, potentially causing the site to malfunction or break.
Impact
Exploitation of this vulnerability could result in the deletion of arbitrary files from the affected WordPress site. If core files are removed, it could disrupt the site's functionality and cause it to stop working properly.
Remediation
Users of the Ovatheme Movie Booking WordPress plugin should update to version 1.1.6 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
