CVE-2016-20082: Abtest
Medium severity, CVSS 6.2. EPSS: 0.3% chance of exploitation in the next 30 days.
WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send GET requests to abtest_admin.php with malicious action values to include files from the admin directory and execute arbitrary code.
Affected products
- Abtest Abtest: version 1.0.6 only
Published 2026-06-15. Last modified 2026-06-17.