Description
WordPress Plugin DukaPress is prone to a directory traversal vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin DukaPress version 2.5.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.5.4 or latest
References
Related Vulnerabilities
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-1580)
WordPress Plugin Easy Accept Payments for PayPal Cross-Site Scripting (4.9.9)
WordPress Plugin Mapplic-Custom Interactive Map Server-Side Request Forgery (6.1)
Atlassian Confluence Unauthenticated Remote Code Execution Vulnerability (CVE-2022-26134)
Joomla Improper Access Control Vulnerability (CVE-2015-7899)