AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-20714

HIGH · CVSS 8.1 EPSS 1.84%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-01-15 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-20714
Severity
HIGH
CVSS
8.1
EPSS
1.84%
WordPress

Original NVD Description

The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.