Beveiligingsadvies

CVE-2026-77757

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-26 06:00:21
Laatst bijgewerkt 2026-08-26 14:43:07
Toegewezen door WPScan
CVSS-score 5.4
Status PUBLISHED

Beschrijving

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does not sanitize a user-supplied image reference before using it as the source of a file move, allowing users with a subscriber-level account to relocate arbitrary server-readable image files into a publicly accessible directory, and to delete them from their original location.