Web Hack List

Later archive addition

WordPress File Delete to Code Execution

A WordPress core flaw allowed an authenticated attacker to manipulate attachment metadata and delete an arbitrary file. Deleting a configuration or protection file could force reinstallation or change server behavior, providing a reliable path from file deletion to remote code execution under common deployments.

Record

Researcher
Karim El Ouerghemmi
Published by
Sonar
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Karim El Ouerghemmi, first published at the original source. Preserved copies are kept so the citation survives its host.