CVE-2024-11613: wp-file-upload
## The Exploit An unauthenticated attacker can read or delete arbitrary files from the server by supplying a path-traversal sequence in the `source` parameter to `wfu_file_downloader.php`. ```http GET /wp-content/plugins/wp-file-upload/li...
Read article →