Description
WordPress Plugin Events Calendar for Google is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Events Calendar for Google version 2.1.0 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable and remove the plugin until a fix is available
References
Related Vulnerabilities
Cherokee Improper Input Validation Vulnerability (CVE-2009-4489)
WordPress Plugin Better WordPress reCAPTCHA (with no CAPTCHA reCAPTCHA) Cross-Site Scripting (2.0.3)
WordPress Plugin Premium Addons for Elementor Cross-Site Scripting (3.7.2)
WordPress Plugin Fancy Product Designer-WooCommerce Cross-Site Request Forgery (4.7.5)