Description
WordPress Plugin article2pdf is prone to multiple vulnerabilities, including arbitrary file deletion and arbitrary file disclosure vulnerabilities. An attacker can exploit these vulnerabilities to delete arbitrary files or to view local files in the context of the web server process, which may aid in launching further attacks. WordPress Plugin article2pdf version 0.27 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
MySQL CVE-2020-2752 Vulnerability (CVE-2020-2752)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-4041)
WordPress Plugin Bird Feeder Multiple Vulnerabilities (1.2.3)
Apache Tomcat Uncontrolled Resource Consumption Vulnerability (CVE-2020-11996)
WordPress Ultimate Member Plugin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-8520)