Description
WordPress Plugin Duplicator-WordPress Migration is prone to an arbitrary file disclosure vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in launching further attacks. WordPress Plugin Duplicator-WordPress Migration version 0.3.0 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
Related Vulnerabilities
WordPress Plugin Premium Addons for Elementor Security Bypass (4.5.1)
WordPress Plugin GigPress Multiple Vulnerabilities (2.3.10)
WordPress Plugin Light Post 'abspath' Parameter Remote File Include (1.4)
WordPress Plugin Magic Post Voice Cross-Site Scripting (1.2)
WordPress Plugin Another WordPress Classifieds Arbitrary File Upload (3.3.2)