Description
WordPress Plugin Content Blocks (Custom Post Widget) is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Content Blocks (Custom Post Widget) version 3.3.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.3.1 or latest
References
Related Vulnerabilities
WordPress Plugin Product Addons & Fields for WooCommerce Cross-Site Scripting (32.0.6)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5492)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2021-4104)
WordPress Plugin Store Locator Plus for WordPress Cross-Site Scripting (5.5.15)
WordPress Plugin The Plus Addons for Elementor Security Bypass (4.1.10)