PT-2026-41465 · Miniorange · Backuprestore
Murat Demirci
·
Published
2026-05-16
·
Updated
2026-05-16
·
CVE-2021-47979
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers can send POST requests to admin-ajax.php with crafted file name and folder name parameters to delete arbitrary files from the WordPress installation directory.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Backuprestore