Description
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.
Remediation
References
Related Vulnerabilities
XOOPS Other Vulnerability (CVE-2005-2113)
Oracle Application Server CVE-2008-0344 Vulnerability (CVE-2008-0344)
WordPress Plugin Velvet Blues Update URLs Unspecified Vulnerability (2.1)
Oracle Database Server CVE-2006-5337 Vulnerability (CVE-2006-5337)
WordPress Plugin Realty by BestWebSoft Cross-Site Scripting (1.0.9)