#VU17725 Path traversal in WP Cost Estimation
Published: February 16, 2019
WP Cost Estimation
Loopus Plugins
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request, upload arbitrary file to the system and overwrite files, present on the server. Successful exploitation of this vulnerability may result in system compromise.
Note: this vulnerability is being actively exploited in the wild.