Description
Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.
Remediation
References
Related Vulnerabilities
MySQL CVE-2016-3424 Vulnerability (CVE-2016-3424)
Python Integer Overflow or Wraparound Vulnerability (CVE-2008-1679)
MySQL CVE-2020-2686 Vulnerability (CVE-2020-2686)
WordPress Plugin Easy Filter SQL Injection (1.5)
WordPress Plugin WooCommerce PDF Invoices & Packing Slips Cross-Site Scripting (2.0.12)