Description
Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.
Remediation
References
Related Vulnerabilities
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-3278)
WordPress Plugin Twenty20 Image Before-After Malicious Code (1.6.3)
axios Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2026-44486)