Description
WordPress Plugin cloudsafe365_for_WP is prone to a file disclosure vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability to view local files in the context of the web server process; this may aid in launching further attacks. WordPress Plugin cloudsafe365_for_WP version 1.46 is vulnerable.
Remediation
Update to plugin version 1.47 or latest
References
http://www.securityfocus.com/bid/55241/exploit
http://packetstormsecurity.com/files/115972/WordPress-Cloudsafe365-Local-File-Inclusion.html
Related Vulnerabilities
WordPress 5.3.x Multiple Vulnerabilities (5.3)
Oracle JRE CVE-2023-21937 Vulnerability (CVE-2023-21937)
Resin Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2969)
WordPress Plugin Hide Featured Image Unspecified Vulnerability (1.1)
Jboss EAP Incorrect Authorization Vulnerability (CVE-2019-14843)