Files
CVEs-PoC/2016/CVE-2016-7169.md
2025-09-29 21:09:30 +02:00

969 B

CVE-2016-7169

Description

Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.

POC

Reference

Github