PatchSiren

abtest CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM abtest CVE published 2026-06-15

CVE-2016-20082

CVE-2016-20082 is a local file inclusion vulnerability in the WordPress Plugin Abtest. This vulnerability allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send GET requests to abtest_admin.php with malicious action values to include files from the admin directory and execute arbitrary code.