Description
WordPress Plugin Flamingo is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary code within the context of the affected webserver process; this may result in total compromise of the web server. WordPress Plugin Flamingo version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.1 or latest
References
Related Vulnerabilities
WordPress Cookies Security Bypass Weakness (1.5 - 2.3.1)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2016-5096)
WordPress Plugin Caldera Forms-More Than Contact Forms Arbitrary File Disclosure (1.8.1)
Apache HTTP Server CVE-2012-0883 Vulnerability (CVE-2012-0883)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.15.42)