Local File Inclusion Vulnerability in Dharma Booking Plugin by WordPress
CVE-2016-20079

6.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2016-20079?

The Dharma Booking plugin for WordPress, specifically versions 2.28.3 and earlier, is susceptible to a local file inclusion vulnerability due to improper sanitation of the gateway parameter. This flaw permits unauthenticated attackers to manipulate file paths and execute directory traversal or null byte injection techniques. As a result, attackers may gain unauthorized access to sensitive files, including configuration and system files, which could compromise the integrity of the affected website.

Affected Version(s)

Dharma Booking 0 <= 2.28.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

AMAR^SHG
.