CyberRota Analysis
AI-GeneratedThe FunnelKit WordPress plugin prior to version 3.15.0.6 is vulnerable to a path traversal attack, enabling users with administrator privileges to delete arbitrary .json files outside the designated directory during template-import operations. This flaw can lead to denial of service by disabling other instances of the FunnelKit plugin. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.
Original NVD Description
The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory through path traversal, which can disable other FunnelKit WordPress plugin before 3.15.0.6 or (denial of service).