CVE-2015-5482: DEV4PRESS Gd Bbpress Attachments
Medium severity, CVSS 4.0. EPSS: 1.8% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.
Affected products
- DEV4PRESS Gd Bbpress Attachments: up to and including 2.2
Published 2015-08-18. Last modified 2026-06-17.