Description
WordPress Plugin Awesome Support-WordPress HelpDesk & Support is prone to multiple vulnerabilities, including arbitrary file deletion and arbitrary file disclosure vulnerabilities. An attacker can exploit these vulnerabilities to delete arbitrary files or to view local files in the context of the web server process, which may aid in launching further attacks. WordPress Plugin Awesome Support-WordPress HelpDesk & Support version 4.3.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.3.2 or latest
References
Related Vulnerabilities
WordPress Plugin WebP Express Arbitrary File Disclosure (0.14.10)
Oracle Database Server CVE-2015-2599 Vulnerability (CVE-2015-2599)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-32477)
WordPress Plugin Properties and Agents-Real Estate Manager Cross-Site Scripting (6.7.1)