Description
WordPress Plugin Be POPIA Compliant is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Be POPIA Compliant version 1.1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.6 or latest
References
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1186
https://plugins.svn.wordpress.org/be-popia-compliant/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Gravity Forms FreshDesk Cross-Site Scripting (1.2.8)
WordPress Plugin Yoast SEO Cross-Site Scripting (20.2)
WordPress Plugin AVK-Shop Multiple Cross-Site Scripting Vulnerabilities (1.1.1)
WordPress Plugin Sina Extension for Elementor Local File Inclusion (2.2.0)
PrestaShop Files or Directories Accessible to External Parties Vulnerability (CVE-2020-5250)