Description
WordPress Plugin Flamingo is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary code within the context of the affected webserver process; this may result in total compromise of the web server. WordPress Plugin Flamingo version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.1 or latest
References
Related Vulnerabilities
Ruby on Rails Inefficient Regular Expression Complexity Vulnerability (CVE-2023-22795)
Microsoft SQL Server Other Vulnerability (CVE-2000-0199)
Internet Information Services Other Vulnerability (CVE-1999-0448)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Local File Inclusion (1.5.24)