Description
WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send GET requests to abtest_admin.php with malicious action values to include files from the admin directory and execute arbitrary code.
Problem types
Product status
Credits
CrashBandicot
References
www.exploit-db.com/exploits/39577 (ExploitDB-39577)
github.com/wp-plugins/abtest (Official Product Homepage)
www.vulncheck.com/...cal-file-inclusion-via-abtest-admin-php (VulnCheck Advisory: WordPress Plugin Abtest Local File Inclusion via abtest_admin.php)