WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers can send POST requests to admin-ajax.php with crafted file_name and folder_name parameters to delete arbitrary files from the WordPress installation directory.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-16 16:16
Updated : 2026-06-17 04:18
NVD link : CVE-2021-47979
Mitre link : CVE-2021-47979
CVE.ORG link : CVE-2021-47979
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
