๐Ÿ” CVE Alert

CVE-2016-20082

MEDIUM 6.2

WordPress Plugin Abtest Local File Inclusion via abtest_admin.php

CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th

WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send GET requests to abtest_admin.php with malicious action values to include files from the admin directory and execute arbitrary code.

CWE CWE-98
Vendor abtest
Product abtest
Published Jun 15, 2026
Last Updated Jun 15, 2026
Stay Ahead of the Next One

Get instant alerts for abtest abtest

Be the first to know when new medium vulnerabilities affecting abtest abtest are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

abtest / Abtest
1.0.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/39577 github.com: https://github.com/wp-plugins/abtest vulncheck.com: https://www.vulncheck.com/advisories/wordpress-plugin-abtest-local-file-inclusion-via-abtest-admin-php

Credits

CrashBandicot