{ "schema_version": "1.4.0", "id": "GHSA-w8vh-gv77-c8pw", "modified": "2022-01-12T00:01:48Z", "published": "2022-01-04T00:00:47Z", "aliases": [ "CVE-2021-25021" ], "details": "The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-25021" }, { "type": "WEB", "url": "https://wpscan.com/vulnerability/92db763c-ca6b-43cf-87ff-c1678cf4ade5" } ], "database_specific": { "cwe_ids": [ "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2022-01-03T13:15:00Z" } }