← WordPress Vulnerabilities
WordPress security by component

Photocart Link

Photocart Link is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 6.9.

Plugin slug: photocart-link

CVE-2016-20077: Photocart Link: Filesystem traversal

Photocart Link is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is 1.6.

PublishedJun 15, 2026
Safe version guidanceSee mitigation notes
Safe version
Jun 15, 2026 CVE-2016-20077
Photocart Link: Filesystem traversal
Photocart Link is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is 1.6.
See mitigation notes
CVE6.9
NVDPending