Description
WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.
Remediation
References
Related Vulnerabilities
WordPress Plugin Under Construction Open Redirect (3.20)
Apache HTTP Server CVE-2013-1896 Vulnerability (CVE-2013-1896)
Oracle Database Server CVE-2018-2575 Vulnerability (CVE-2018-2575)
WordPress Plugin Ultimate Gift Cards For WooCommerce Cross-Site Request Forgery (2.1.1)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-0499)