Description
Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.
References (4)
Core 4
Core References
Patch x_refsource_confirm
https://wordpress.org/plugins/gd-bbpress-attachments/changelog/
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/8087
Exploit x_refsource_misc
https://security.dxw.com/advisories/local-file-include-vulnerability-in-gd-bbpress-attachments-allows-attackers-to-include-arbitrary-php-files/
Exploit x_refsource_misc
https://packetstormsecurity.com/files/132656/wpgdbbpress-lfi.txt
Scores
EPSS
0.0181
EPSS Percentile
75.9%
Details
CWE
CWE-22
Status
published
Products (1)
dev4press/gd_bbpress_attachments
< 2.2
Published
Aug 18, 2015
Tracked Since
Feb 18, 2026