Vulnerability Description
The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ffw | Optimize My Google Fonts | < 4.5.12 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/92db763c-ca6b-43cf-87ff-c1678cf4ade5ExploitThird Party Advisory
- https://wpscan.com/vulnerability/92db763c-ca6b-43cf-87ff-c1678cf4ade5ExploitThird Party Advisory
FAQ
What is CVE-2021-25021?
CVE-2021-25021 is a vulnerability with a CVSS score of 4.9 (MEDIUM). The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary fol...
How severe is CVE-2021-25021?
CVE-2021-25021 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25021?
Check the references section above for vendor advisories and patch information. Affected products include: Ffw Optimize My Google Fonts.