The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
References
Link Resource
http://seclists.org/fulldisclosure/2018/Sep/32 Exploit Mailing List Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/150202 Third Party Advisory VDB Entry
https://github.com/springjk/wordpress-wechat-broadcast/issues/14 Issue Tracking Third Party Advisory
https://wpvulndb.com/vulnerabilities/9132 Exploit Third Party Advisory
https://www.exploit-db.com/exploits/45438/ Exploit Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-09-24T22:00:00

Updated: 2018-09-25T09:57:01

Reserved: 2018-08-31T00:00:00


Link: CVE-2018-16283

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-09-24T22:29:00.957

Modified: 2018-11-14T14:50:39.230


Link: CVE-2018-16283

JSON object: View

cve-icon Redhat Information

No data.

CWE