CVE-2016-20081

HIGH

WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20081. PoCs published by CrashBandicot.

AI-analyzed exploit summary This exploit demonstrates an arbitrary file download vulnerability in the WordPress plugin HB Audio Gallery Lite. The vulnerability arises from improper handling of user-supplied input in the 'file_path' parameter, allowing attackers to download sensitive files like 'wp-config.php'.

Description

WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the file_path parameter. Attackers can send requests to the audio-download.php endpoint with directory traversal sequences to access sensitive files like wp-config.php outside the intended gallery directory.

Exploits (1)

exploitdb WORKING POC VERIFIED
by CrashBandicot · textwebappsphp
https://www.exploit-db.com/exploits/39589

This exploit demonstrates an arbitrary file download vulnerability in the WordPress plugin HB Audio Gallery Lite. The vulnerability arises from improper handling of user-supplied input in the 'file_path' parameter, allowing attackers to download sensitive files like 'wp-config.php'.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin HB Audio Gallery Lite 1.0.0
No auth needed
Prerequisites: Access to the vulnerable plugin endpoint
devstral-2 · analyzed Jun 15, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-39589
https://www.exploit-db.com/exploits/39589
Product product
Official Product Homepage
https://fr.wordpress.org/plugins/hb-audio-gallery-lite/
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download
https://www.vulncheck.com/advisories/wordpress-plugin-hb-audio-gallery-lite-path-traversal-file-download

Scores

CVSS v3 7.5
EPSS 0.0064
EPSS Percentile 45.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
Husain/HB Audio Gallery Lite 1.0.0
Published Jun 15, 2026
Tracked Since Jun 15, 2026