Description
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.
Remediation
References
Related Vulnerabilities
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-33331)
Nginx Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0337)
Oracle Database Server CVE-2018-2680 Vulnerability (CVE-2018-2680)
Perl Numeric Errors Vulnerability (CVE-2013-7422)
WordPress Plugin WP Cerber Security, Anti-spam & Malware Scan Cross-Site Scripting (9.1)