CVE-2021-24639
20.09.2021, 10:15
The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.
Vendor | Product | Version |
---|---|---|
ffw | omgf | 𝑥 < 4.5.4 |
𝑥
= Vulnerable software versions