Back to overview

CVE-2016-20078

MEDIUM
6.2
CVSS 3.1
Description
WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the url parameter. Attackers can supply directory traversal sequences in GET requests to pic.php to access sensitive files like wp-config.php containing database credentials and configuration data.

Metadata

CVE ID
CVE-2016-20078
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-15 11:45 UTC
Published
2026-06-15 12:00 UTC
Last updated
2026-06-15 12:00 UTC
Primary CWE
CWE-98
Improper Control of Filename for Include/Require Statement i…
Vendor / Product
Henrique Dias / IMDb Profile Widget
Sources
cve.org  ·  NVD

Severity & Metrics

6.2 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products (1)
VendorProductPlatformVersions
Henrique Dias IMDb Profile Widget 1.0.8
Weakness (CWE)
CWESourceDescription
CWE-98 cna Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVSS scores (2)
ScoreSeverityVersionSourceVector
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
6.2 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References (3)
Back to overview