Description
Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field <= 1.0.6 versions.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version
Credits
babyhack(@OPCIA) | Patchstack Bug Bounty Program
References
patchstack.com/...rary-file-deletion-vulnerability?_s_id=cve