The Hummingbird WordPress plugin before 3.4.2 does not...
Critical severity
Unreviewed
Published
Apr 10, 2023
to the GitHub Advisory Database
•
Updated Apr 22, 2023
Description
Published by the National Vulnerability Database
Apr 10, 2023
Published to the GitHub Advisory Database
Apr 10, 2023
Last updated
Apr 22, 2023
The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.
References