Description
WordPress Plugin Cimy User Extra Fields is prone to a Denial of Service vulnerability. Exploiting this issue allows an attacker to delete random server files and 'hide' multiple files on the server, thus denying service to legitimate users. WordPress Plugin Cimy User Extra Fields version 2.6.3 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 2.6.4 or latest
References
Related Vulnerabilities
XWiki Cleartext Storage of Sensitive Information Vulnerability (CVE-2023-50719)
Oracle JRE CVE-2022-21541 Vulnerability (CVE-2022-21541)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2021-4104)
Roundcube Multiple Cross-site Request Forgery (CSRF) Vulnerabilities (CVE-2014-9587)
WordPress Plugin Shortcode for Font Awesome Cross-Site Scripting (1.4)