Description
WordPress Plugin Advanced XML Reader is prone to an information disclosure vulnerability because it fails to properly sanitize user-supplied input. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Advanced XML Reader version 0.3.4 is vulnerable; other versions may also be affected.
Remediation
Disable the plugin
References
http://packetstormsecurity.com/files/121492/WordPress-Advanced-XML-Reader-0.3.4-XXE-Injection.html
http://1337day.com/exploit/20728
http://wordpress.org/support/topic/do-not-use-this-plugin-anymore
Related Vulnerabilities
WordPress Possible SQL Injection Vulnerability (0.70 - 3.6.1)
WordPress Plugin PowerPack for Beaver Builder Privilege Escalation (2.33.0)
WordPress Plugin WP Construction Mode Cross-Site Request Forgery (1.91)
Atlassian Confluence Uncontrolled Search Path Element Vulnerability (CVE-2021-43940)
MySQL Cleartext Transmission of Sensitive Information Vulnerability (CVE-2017-3305)