Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2016-20080 2 Brandfolder, Wordpress 2 Brandfolder, Wordpress 2026-06-23 6.2 Medium
WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_abspath parameter to read sensitive files like wp-config.php or execute remote code.