Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 23 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kaymeephotography
Kaymeephotography photocart Link Wordpress Wordpress wordpress |
|
| Vendors & Products |
Kaymeephotography
Kaymeephotography photocart Link Wordpress Wordpress wordpress |
Mon, 15 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in decode.php. Attackers can supply base64-encoded file paths in the 'id' parameter to the decode.php endpoint to retrieve sensitive files like wp-config.php containing database credentials and configuration data. | |
| Title | WordPress Plugin Photocart Link 1.6 Local File Inclusion via decode.php | |
| Weaknesses | CWE-98 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-15T15:13:23.880Z
Reserved: 2026-06-15T11:44:39.821Z
Link: CVE-2016-20077
Updated: 2026-06-15T15:13:18.628Z
Status : Deferred
Published: 2026-06-15T14:16:31.077
Modified: 2026-06-15T20:50:47.973
Link: CVE-2016-20077
No data.
OpenCVE Enrichment
Updated: 2026-06-23T21:09:22Z