WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php
Vulnerability Description
WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_abspath parameter to read sensitive files like wp-config.php or execute remote code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-20080
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- AMAR^SHG
Affected Vendor
Brandfolder
View all reports →