Author → arbitrary file deletion anywhere on disk, leading to site takeover
A newly added REST route, POST /wp/v2/media/<id>/finalize, stored an attacker-supplied path verbatim in attachment metadata. Laundering it through the image editor moved it into protected meta, where the deletion routine built its directory guard from that same poisoned value — so the guard constrained nothing. The lowest role allowed to upload files could delete wp-config.php, or files outside the document root entirely.
- Class
- Path traversal · CWE-22
- Privilege
- Author — lowest role with
upload_files - Status
- Resolved · disclosed 28 Aug 2026