What the vulnerability does
01Description
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
Explanation of Vulnerability in Simple Terms
Kali Forms versions up to 2.4.18 contain a path traversal vulnerability that allows authenticated users to cause a denial of service by disrupting site availability. An attacker with low-level access can exploit this flaw remotely without user interaction. The vulnerability affects the entire site due to scope change, making it a significant availability risk for WordPress installations using this plugin.
What an attacker can do
Disrupt site availability and cause denial of service through path traversal exploitation.
Potential impact on your site
Site availability can be disrupted by authenticated attackers, potentially taking the site offline.
Conditions required to exploit
Attacker must have low-level user account access; no user interaction required.
Key dates
External resources
Related vulnerabilities