Description
WordPress Plugin ExS Widgets is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin ExS Widgets version 0.3.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.3.2 or latest
References
Related Vulnerabilities
WebLogic Other Vulnerability (CVE-2022-24891)
WordPress Plugin WP Link To Us Multiple Cross-Site Scripting Vulnerabilities (2.0)
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2006-0114)
WordPress Plugin Maps Widget for Google Maps-Google Maps Builder Cross-Site Scripting (2.30)