Description
WordPress Plugin Startklar Elementor Addons is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to delete arbitrary files in the context of the webserver process. WordPress Plugin Startklar Elementor Addons version 1.7.13 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.14 or latest
References
Related Vulnerabilities
WordPress Possible SQL Injection Vulnerability (0.70 - 3.6.1)
WordPress Plugin DVS Custom Notification Multiple Cross-Site Request Forgery Vulnerabilities (1.0.1)
MyBB Server-Side Request Forgery (SSRF) Vulnerability (CVE-2017-7566)
WordPress Plugin Launcher:Coming Soon & Maintenance Mode Cross-Site Scripting (1.0.10)