vanquish User Extra Fields
cpe:2.3:a:vanquish:user_extra_fields:*:*:*:*:wordpress:*:*
- <= 17.0
A path traversal vulnerability has been identified in the WordPress User Extra Fields plugin, specifically in versions through 17.0. This vulnerability allows for improper limitation of a pathname, potentially leading to arbitrary file deletion. Such deletion could disrupt website functionality by removing essential core files.
Exploitation of this vulnerability could result in the deletion of arbitrary files from the affected WordPress site. If critical core files are removed, it may cause the website to malfunction or become nonoperational.
Users are advised to mitigate this vulnerability immediately. Patchstack has provided a mitigation rule to block potential attacks until an official patch is available. For more information on how to apply this mitigation, visit the Patchstack website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.