Unrated severityNVD Advisory· Published Dec 16, 2025· Updated Apr 7, 2026
WebsiteBaker 2.13.3 Directory Traversal via Media Delete Endpoint
CVE-2023-53902
Description
WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2= 2.13.3+ 1 more
- (no CPE)range: = 2.13.3
- (no CPE)range: 2.13.3
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/51554mitreexploit
- www.vulncheck.com/advisories/websitebaker-directory-traversal-via-media-delete-endpointmitrethird-party-advisory
- websitebaker.org/pages/en/home.phpmitreproduct
News mentions
0No linked articles in our index yet.