CVE-2016-20080
Published
CVSS v3
6.2
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_abspath parameter to read sensitive files like wp-config.php or execute remote code.
<blockquote>
<p>This plugin requires a Brandfolder account which you can setup at <a href="http://brandfolder.com" rel="nofollow ugc">Brandfolder.com</a></p>
</blockquote>
<p>This plugin provides one block and is only compatible with the Gutenberg editor at this time.</p>
<h3>Features of the Brandfolder WordPress plugin</h3>
<ul>
<li>Edit your Brandfolders directly from your WordPress admin panel.</li>
<li>Easily embed your Brandfolder using our Popup Embed on any widget, menu bar, page, or post.</li>
<li>The Brandfolder integration allows you to quickly grab assets from your Brandfolders to be used in Pages/Posts.</li>
<li>Use the [Brandfolder] shortcode in either widgets, pages, or posts to quickly create a Popup Embed link: <code>[Brandfolder id="mapmyfitness" collection="mapmyrun" query="" text="View our Brandfolder" classes="brandfolder"]</code></li>
</ul>
<p>Read all about the different embed options on the <a href="https://help.smartsheet.com/115002673674-Wordpress-Integration" rel="nofollow ugc">Brandfolder Knowledge Base</a>.</p>
<h3>Support</h3>
<ul>
<li>
<p>Visit https://help.smartsheet.com/brandfolder for support & documentation.</p>
</li>
<li>
<p>We also recommend the <a href="http://en.support.wordpress.com/" rel="nofollow ugc">WordPress Support</a> for extended help.</p>
</li>
</ul>
<h3>External services</h3>
<p>This plugin connects to external Brandfolder services to provide digital asset management functionality. The plugin communicates with the following external services:</p>
<p><strong>Brandfolder CDN and API Services</strong><br />
* <strong>Service</strong>: Brandfolder’s content delivery network and API services<br />
* <strong>Purpose</strong>: To load the Brandfolder JavaScript library, display assets, and enable asset selection functionality<br />
* <strong>Data sent</strong>: When users interact with Brandfolder embeds or select assets, the plugin may send:<br />
– Brandfolder account identifiers<br />
– Collection and asset query parameters<br />
– User interaction data for asset selection<br />
* <strong>When data is sent</strong>: Data is transmitted when:<br />
– The Brandfolder embed is loaded on a page<br />
– Users click on Brandfolder links or buttons<br />
– Assets are selected or embedded from Brandfolder<br />
* <strong>External domains used</strong>:<br />
– <code>cdn.brandfolder.com</code> – For loading the Brandfolder JavaScript library<br />
– <code>integration-panel-ui.brandfolder-svc.com</code> – For the asset selection interface<br />
– <code>brandfolder.com</code> – For direct links to Brandfolder collections</p>
<p><strong>Legal Information</strong>:<br />
* Brandfolder Terms of Service: https://brandfolder.com/terms-of-service<br />
* Brandfolder Privacy Policy: https://brandfolder.com/privacy-policy</p>
<p>By using this plugin, you acknowledge that your website will connect to these external Brandfolder services. Please ensure this complies with your website’s privacy policy and terms of service.</p>