CVE-2024-7856: mp3-music-player-by-sonaar
## The Exploit An authenticated WordPress user with subscriber-level access (or above) can delete arbitrary files on the server by sending a specially crafted AJAX request that bypasses path traversal validation. ```http POST /wp-admin/ad...
Read article →