Description
Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin CopySafe PDF Protection Arbitrary File Upload (0.6)
ownCloud Exposure of Resource to Wrong Sphere Vulnerability (CVE-2020-36252)
WordPress Plugin MP3-jPlayer Multiple Cross-Site Scripting Vulnerabilities (1.8.7)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2359)