#VU8508 Path traversal in WordPress - CVE-2017-14719
Published: September 20, 2017 / Updated: October 2, 2017
WordPress
WordPress.ORG
Description
The vulnerability allows a remote attacker to read arbitrary files on the system.
The vulnerability exists due to insufficient sanitization of user-supplied data in the file unzipping code in the ZipArchive and PclZip components. A remote attacker can send a specially crafted HTTP request containing directory traversal sequences and view contest of arbitrary file on vulnerable system.