Launchpad.net

CVE 2018-20147

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.

See the CVE page on Mitre.org for more details.