First published: Sun Mar 12 2017(Updated: )
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=4.7.2 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6816 is considered to be of medium severity due to its potential for unauthorized file deletion by administrators.
To fix CVE-2017-6816, upgrade WordPress to version 4.7.3 or later.
CVE-2017-6816 affects WordPress versions prior to 4.7.3, as well as certain Debian Linux distributions.
CVE-2017-6816 is classified as a privilege escalation vulnerability related to file deletion.
CVE-2017-6816 can potentially be exploited by any authenticated administrator accessing the plugin deletion functionality.