OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy., CVE-2021-24639
- CVE, Research URL
- Published on
- Sep 20, 2021
- Research Description
- The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.
- Affected versions
-
max 4.5.4.
- Status
-
vulnerable