Vulnerability Description
WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_abspath parameter to read sensitive files like wp-config.php or execute remote code.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://brandfolder.com
- https://wordpress.org/plugins/brandfolder/
- https://www.exploit-db.com/exploits/39591
- https://www.vulncheck.com/advisories/wordpress-brandfolder-plugin-local-file-inc
FAQ
What is CVE-2016-20080?
CVE-2016-20080 is a vulnerability with a CVSS score of 6.2 (MEDIUM). WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the ...
How severe is CVE-2016-20080?
CVE-2016-20080 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-20080?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.