Description
WordPress Plugin article2pdf is prone to multiple vulnerabilities, including arbitrary file deletion and arbitrary file disclosure vulnerabilities. An attacker can exploit these vulnerabilities to delete arbitrary files or to view local files in the context of the web server process, which may aid in launching further attacks. WordPress Plugin article2pdf version 0.27 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
Sqlite NULL Pointer Dereference Vulnerability (CVE-2020-13435)
WordPress 4.3.x Multiple Vulnerabilities (4.3 - 4.3.5)
Oracle Database Server CVE-2015-0373 Vulnerability (CVE-2015-0373)
WordPress Plugin Comments-wpDiscuz Cross-Site Scripting (3.1.4)
WordPress 3.8.x Cross-Site Scripting Vulnerability (3.8 - 3.8.11)