CVE-2019-14206
60Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 4.7%
from disclosure to weapon2359 days
Published on NVDJul 21
1st PoC+2359d
VulnCheckJul 19
exploitation probability
4.7%top 9% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to delete arbitrary files via the $REQUEST['adaptive-images-settings'] parameter in adaptive-images-script.php.
Affected products
n/a · n/apublic PoCs found — 1
vulncheckvulncheck.com/xdb/035026519e5bunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/markgruffer/markgruffer.github.io/blob/master/_posts/2019-07-19-adaptive-images-for-wordpress-0-6-66-lfi-rce-file-deletion.markdownhttps://markgruffer.github.io/2019/07/19/adaptive-images-for-wordpress-0-6-66-lfi-rce-file-deletion.htmlhttps://wordpress.org/plugins/adaptive-images/#developershttps://wpvulndb.com/vulnerabilities/9468