PT-2026-49218 · Undefined · Undefined

Published

2026-06-15

·

Updated

2026-06-15

·

CVE-2016-20080

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp abspath parameter to read sensitive files like wp-config.php or execute remote code.

Fix

Weakness Enumeration

Related Identifiers

CVE-2016-20080

Affected Products

Undefined