WordPress Brandfolder - Open Redirect (RFI & LFI)
WordPress Brandfolder is vulnerable to remote/local file inclusion and allows remote attackers to inject an arbitrary URL into the 'callback.php' endpoint via the 'wp_abspath' parameter which will redirect the victim to it.
BrandfolderPoC 已收录
CVSS—