Unrated severityNVD Advisory· Published Dec 16, 2025· Updated Apr 7, 2026
WebsiteBaker 2.13.3 Directory Traversal via Media Delete Endpoint
CVE-2023-53902
Description
WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory.
Affected products
1- Range: 2.13.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/51554mitreexploit
- www.vulncheck.com/advisories/websitebaker-directory-traversal-via-media-delete-endpointmitrethird-party-advisory
- websitebaker.org/pages/en/home.phpmitreproduct
News mentions
0No linked articles in our index yet.