CVE

Id
93716  
CVE No.
CVE-2016-6896  
Status
Candidate  
Description
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to wp-admin/admin-ajax.php, as demonstrated by /dev/random read operations that deplete the entropy pool.  
Phase
Assigned (20160822)  
Votes
None (candidate not yet proposed)  
Comments