CVE-2016-20082
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
15/06/2026
Last modified:
15/06/2026
Description
WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send GET requests to abtest_admin.php with malicious action values to include files from the admin directory and execute arbitrary code.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
6.20
Severity 3.x
MEDIUM



