Critical severity9.8OSV Advisory· Published Sep 24, 2018· Updated Jun 17, 2026
CVE-2018-16283
CVE-2018-16283
Description
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: v1.0.0-beta, v1.1.2, v1.2.0
- cpe:2.3:a:wechat_brodcast_project:wechat_brodcast:*:*:*:*:*:wordpress:*:*Range: <=1.2.0
- Range: <=1.2.0
Patches
Vulnerability mechanics
References
5- seclists.org/fulldisclosure/2018/Sep/32nvdExploitMailing ListThird Party Advisory
- wpvulndb.com/vulnerabilities/9132nvdExploitThird Party Advisory
- www.exploit-db.com/exploits/45438/nvdExploitThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/150202nvdThird Party AdvisoryVDB Entry
- github.com/springjk/wordpress-wechat-broadcast/issues/14nvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.