Description
WordPress Plugin Advanced Classifieds & Directory Pro is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Advanced Classifieds & Directory Pro version 3.1.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.1 or latest
References
Related Vulnerabilities
IBM WebSEAL Use of Hard-coded Credentials Vulnerability (CVE-2018-1887)
WordPress Plugin Content Blocks (Custom Post Widget) Local File Inclusion (3.3.0)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-3230)
WordPress Plugin Catch Under Construction Security Bypass (1.3.4)