
🚨 CVE-2016-15033: Ganesh Chandra (CVSS: 9.8)... Unauthenticated file upload in Delete All Comments plugin provides direct RCE pathway via delete-all-comments.php - tri... https://zerodaysignal.com/vulnerability/CVE-2016-15033 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The post announces CVE-2016-15033 as an unauthenticated file‑upload flaw in the Delete All Comments plugin that allows remote code execution, with a CVSS score of 9.8. No evidence of PoC, exploit code, active attacks, or patches is provided.
