nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-20079 CVE-2016-20079
MEDIUM
WordPress Dharma Booking 2.28.3 Local File Inclusion via proccess.php
Record summary
CVE-2016-20079 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.
Description
WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the gateway parameter. Attackers can supply file paths with directory traversal sequences or null byte injection to the gateway parameter in proccess.php to read sensitive files like configuration and system files.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 15, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Dharma BookingBrowse jamie / Dharma Booking | CVE List | Through 2.28.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Dharma Booking 2.38.3 - Remote File InclusionExploitDB exploitby AMAR^SHGNot analyzed1 file
References
4Official Product Homepageproduct
https://wordpress.org/plugins/dharma-booking ExploitDB-39592exploit
https://www.exploit-db.com/exploits/39592 VulnCheck Advisory: WordPress Dharma Booking 2.28.3 Local File Inclusion via proccess.phpThird-party advisory
https://www.vulncheck.com/advisories/wordpress-dharma-booking-local-file-inclusion-via-proccess-php