Description
Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.
Remediation
References
Related Vulnerabilities
Contao Improper Input Validation Vulnerability (CVE-2020-25768)
WordPress Plugin Accept Signups 'email' Parameter Cross-Site Scripting (0.1)
Django Uncontrolled Resource Consumption Vulnerability (CVE-2023-24580)
WordPress Plugin Feed Statistics Open Redirect (3.0)
Joomla Missing Authentication for Critical Function Vulnerability (CVE-2019-10946)