Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to wp-admin/admin-ajax.php, as demonstrated by /dev/random read operations that deplete the entropy pool.
2017-01-18T21:59:00.277
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.1 (HIGH)
AV:N/AC:L/Au:S/C:P/I:N/A:P
8.0
4.9