Description
The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.0 via the 'zetra_deleteLanguageFile' and 'zetra_deleteFontsFile' functions. This is due to the plugin not properly validating a file or its path prior to deleting it. This makes it possible for unauthenticated attackers to delete language files.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version
Timeline
| 2024-11-22: | Discovered |
| 2025-05-05: | Disclosed |
Credits
István Márton
References
www.wordfence.com/...-4f57-4556-bae9-b0b63a9a43ba?source=cve
themeforest.net/...sulting-business-wordpress-theme/28748459