Description
Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.
Remediation
References
Related Vulnerabilities
WordPress Plugin GigPress 'Notes' Field HTML Injection (2.1.10)
Atlassian Jira CVE-2021-39123 Vulnerability (CVE-2021-39123)
Oracle JRE CVE-2013-2431 Vulnerability (CVE-2013-2431)
WordPress Plugin Advanced AJAX Page Loader Cross-Site Request Forgery (2.7.7)
WordPress Plugin Woocommerce Payment Gateway per Category Cross-Site Scripting (2.0.10)