Wordpress Alert: Archive extraction path traversal
An importer unpacks an archive whose entries target paths outside its destination. Files elsewhere on the server may be overwritten.
What it looks like
An importer unpacks an archive whose entries target paths outside its destination.
Why it matters
Files elsewhere on the server may be overwritten.
What to check
Review archive handling and reject paths outside the extraction root.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP path traversal reference, OWASP file upload guidance.
- Categories: WordPress
- Tags: #WordPress Security, #File Security