Description
WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_abspath parameter to read sensitive files like wp-config.php or execute remote code.
Problem types
Product status
Credits
AMAR^SHG
References
www.exploit-db.com/exploits/39591 (ExploitDB-39591)
brandfolder.com (Official Product Homepage)
wordpress.org/plugins/brandfolder/ (Product Reference)
www.vulncheck.com/...n-local-file-inclusion-via-callback-php (VulnCheck Advisory: WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php)