Related Vulnerabilities: CVE-2016-7169  

A path traversal vulnerability has been discovered in the upgrade package uploader, reported by Dominik Schilling from the WordPress security team.

Severity High

Remote Yes

Type Directory traversal

Description

A path traversal vulnerability has been discovered in the upgrade package uploader, reported by Dominik Schilling from the WordPress security team.

AVG-39 wordpress 4.6.0-1 4.6.1-1 High Fixed

30 Sep 2016 ASA-201609-32 AVG-39 wordpress High multiple issues

http://www.openwall.com/lists/oss-security/2016/09/08/24