WordPress Plugin Buddypress Xprofile Custom Fields Type Arbitrary File Deletion - Vulnerability Database

WordPress Plugin Buddypress Xprofile Custom Fields Type Arbitrary File Deletion

Medium
Reference: No Reference
Title: WordPress Plugin Buddypress Xprofile Custom Fields Type Arbitrary File Deletion
Overview:

WordPress Plugin Buddypress Xprofile Custom Fields Type is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to delete arbitrary files in the context of the webserver process. WordPress Plugin Buddypress Xprofile Custom Fields Type version 2.6.3 is vulnerable prior versions may also be affected.