Madara WordPress Plugin Arbitrary File Deletion Vulnerability
Vulnerability
A vulnerability allowing arbitrary file deletion has been identified in the Madara - Core plugin for WordPress, affecting all versions through 2.2.3. The issue arises from inadequate file path validation in the wp_manga_delete_zip() function, enabling unauthenticated attackers to delete arbitrary files on the server. This vulnerability could easily lead to remote code execution if a critical file, such as wp-config.php, is deleted.
Impact
Exploitation of this vulnerability could result in unauthorized deletion of files on the server, potentially leading to remote code execution if a sensitive file is removed.
Remediation
Users are advised to update the Madara - Core plugin to version 2.2.4 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
