Description
WordPress Plugin ApplyOnline-Application Form Builder and Manager is prone to an arbitrary file disclosure vulnerability because it fails to properly verify user-supplied input. An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in launching further attacks. WordPress Plugin ApplyOnline-Application Form Builder and Manager version 1.9.92 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.9.96 or latest
References
Related Vulnerabilities
WordPress Plugin FV Flowplayer Video Player URL Cross-Site Scripting (1.2.11)
WordPress Plugin twitterDash Cross-Site Request Forgery (2.1)
WordPress Plugin Simple SEO Cross-Site Scripting (1.7.91)
WordPress Plugin Contact Form 7 Privilege Escalation (5.0.3)
WordPress Plugin rtMedia for WordPress, BuddyPress and bbPress Cross-Site Scripting (3.7.38)