CVE-2016-20080 | Brandfolder Plugin up to 3.0 on WordPress callback.php wp_abspath filename control (Exploit 39591 / EDB-39591)

SecurityVulns

A vulnerability, which was classified as problematic, has been found in Brandfolder Plugin up to 3.0 on WordPress. Impacted is an unknown function of the file callback.php. This manipulation of the argument wp_abspath causes improper control of filename for include/require statement in php program (‘php remote file inclusion’). This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability appears as CVE-2016-20080. The attack may be initiated remotely. In addition, an exploit is available.VulDB Recent EntriesRead More