CVE-2016-6896 | WordPress 4.5.3 ajax-actions.php wp_ajax_update_plugin path traversal (EDB-40288 / Nessus ID 93111)
A vulnerability was found in WordPress 4.5.3. It has been classified as critical. Affected is the function wp_ajax_update_plugin of the file ajax-actions.php. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2016-6896. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.