The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin
- https://wpscan.com/vulnerability/67398332-b93e-46ae-8904-68419949a124
- https://github.com/20142995/nuclei-templates