CVE-2020-10564: Path Traversal
Published Mar 13, 2020
·Updated
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfuincludelib call.
Affected Software
1 affected component
Iptanus Wordpress File Upload Wordpress<4.13.0
Event History
Mar 13, 2020
CVE Published
via MITRE·10:07 PM
Data Sourced
via MITRE·10:07 PM
Description
Frequently Asked Questions
1
What is CVE-2020-10564?
CVE-2020-10564 is a vulnerability in the File Upload plugin before 4.13.0 for WordPress that allows directory traversal and can lead to remote code execution.
2
How severe is CVE-2020-10564?
CVE-2020-10564 has a severity rating of 9.8 (Critical).
3
How does CVE-2020-10564 affect WordPress File Upload plugin?
CVE-2020-10564 affects the File Upload plugin before version 4.13.0 for WordPress.
4
How can CVE-2020-10564 be exploited?
CVE-2020-10564 can be exploited by uploading a crafted txt file into the lib directory, using a directory traversal technique.
5
How can I fix CVE-2020-10564?
To fix CVE-2020-10564, update the File Upload plugin to version 4.13.0 or later.