The CAOS | Host Google Analytics Locally WordPress plugin...
Moderate severity
Unreviewed
Published
Jan 4, 2022
to the GitHub Advisory Database
•
Updated Jan 18, 2024
Description
Published by the National Vulnerability Database
Jan 3, 2022
Published to the GitHub Advisory Database
Jan 4, 2022
Last updated
Jan 18, 2024
The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin
References