Description
b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.
Remediation
References
Related Vulnerabilities
Perl Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-1238)
WordPress Plugin SlideDeck 2 Lite Responsive Content Slider Local/Remote File Inclusion (2.3.3)
WordPress Plugin YITH WooCommerce Multi Vendor Cross-Site Scripting (3.8.0)
WordPress Plugin YITH WooCommerce Questions and Answers Security Bypass (1.1.9)