In index.php in WonderCMS before 2.4.1, remote attackers can delete arbitrary files via directory traversal.
https://github.com/robiso/wondercms/commit/64efdc4fd974c83cedd221b46e7c3854a81650ec
http://foreversong.cn/archives/1070
https://www.wondercms.com/whatsnew
Source: Mitre, NVD
Published: 2018-02-27
Updated: 2026-06-17
Base Score: 5.5
Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:P
Severity: Medium
Base Score: 4.9
Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS: 0.01368