CVE-2015-5482 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.
Reference
https://packetstormsecurity.com/files/132656/wpgdbbpress-lfi.txt https://security.dxw.com/advisories/local-file-include-vulnerability-in-gd-bbpress-attachments-allows-attackers-to-include-arbitrary-php-files/ https://wordpress.org/plugins/gd-bbpress-attachments/changelog/ https://wpvulndb.com/vulnerabilities/8087
Share on: