← Back to CVE List
CVE-2020-28039
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt