Description
WordPress Plugin ApplyOnline-Application Form Builder and Manager is prone to an arbitrary file disclosure vulnerability because it fails to properly verify user-supplied input. An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in launching further attacks. WordPress Plugin ApplyOnline-Application Form Builder and Manager version 1.9.92 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.9.96 or latest
References
Related Vulnerabilities
WordPress 4.5.x Same Origin Method Execution (SOME) Vulnerability (4.5 - 4.5.1)
WordPress Plugin Radio Buttons for Taxonomies Cross-Site Request Forgery (2.0.5)
WordPress 2.5 Cookie Integrity Protection Unauthorized Access Vulnerability (0.6.2 - 2.5)
WordPress Plugin MailPoet Newsletters (Previous) Cross-Site Scripting (2.6.11)