Wordpress Alert: Arbitrary file deletion
A cleanup or media handler deletes a path supplied by an unauthorized user. Site files or backups may be removed.
What it looks like
A cleanup or media handler deletes a path supplied by an unauthorized user.
Why it matters
Site files or backups may be removed.
What to check
Audit delete actions for capabilities, ownership, and path confinement.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP path traversal reference, WordPress roles and capabilities.
- Categories: WordPress
- Tags: #WordPress Security, #File Security