Vendor
W CMS versions 3.18.0 and earlier are vulnerable to remote code execution and arbitrary file deletion due to insufficient path validation in the media management API.