### [CVE-2021-25020](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25020) ![](https://img.shields.io/static/v1?label=Product&message=CAOS%20%7C%20Host%20Google%20Analytics%20Locally&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=4.1.9%3C%204.1.9%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-22%20Improper%20Limitation%20of%20a%20Pathname%20to%20a%20Restricted%20Directory%20('Path%20Traversal')&color=brighgreen) ### Description The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin ### POC #### Reference - https://wpscan.com/vulnerability/67398332-b93e-46ae-8904-68419949a124 #### Github No PoCs found on GitHub currently.