Blinko <= 1.8.3 contains a path traversal caused by improper path concatenation without verification in the plugin file server endpoint, letting remote attackers access arbitrary files, exploit requires network access.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view