The wpajaxupdateplugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a getplugindata call before checking the updateplugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896.
{
    "binaries": [
        {
            "binary_version": "4.4.2+dfsg-1ubuntu1",
            "binary_name": "wordpress"
        },
        {
            "binary_version": "4.4.2+dfsg-1ubuntu1",
            "binary_name": "wordpress-l10n"
        },
        {
            "binary_version": "4.4.2+dfsg-1ubuntu1",
            "binary_name": "wordpress-theme-twentyfifteen"
        },
        {
            "binary_version": "4.4.2+dfsg-1ubuntu1",
            "binary_name": "wordpress-theme-twentyfourteen"
        },
        {
            "binary_version": "4.4.2+dfsg-1ubuntu1",
            "binary_name": "wordpress-theme-twentysixteen"
        }
    ]
}