Description
WordPress Plugin Aspose Importer & Exporter is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Aspose Importer & Exporter versions 2.0 and prior are vulnerable.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Export any WordPress data to XML/CSV Cross-Site Scripting (1.3.5)
Moodle Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2020-14322)
Drupal Core 9.0.x Multiple Security Bypass Vulnerabilities (9.0.0 - 9.0.14)
WordPress 4.9.x Multiple Vulnerabilities (4.9 - 4.9.12)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1915)