WordPress Plugin WooCommerce Arbitrary File Deletion - CVE-2018-20714 - Vulnerability Database

WordPress Plugin WooCommerce Arbitrary File Deletion - CVE-2018-20714

High
Reference: CVE-2018-20714
Title: WordPress Plugin WooCommerce Arbitrary File Deletion
Overview:

WordPress Plugin WooCommerce is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to delete arbitrary files in the context of the webserver process. WordPress Plugin WooCommerce version 3.4.5 is vulnerable prior versions are also affected.