Description
WordPress Plugin Flamingo is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary code within the context of the affected webserver process; this may result in total compromise of the web server. WordPress Plugin Flamingo version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.1 or latest
References
Related Vulnerabilities
Python Protection Mechanism Failure Vulnerability (CVE-2016-0772)
Moodle Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2008-5153)
WordPress Plugin Asgaros Forum Multiple Vulnerabilities (1.15.14)
PostgreSQL Integer Overflow or Wraparound Vulnerability (CVE-2026-14677)
Oracle JRE Insecure Storage of Sensitive Information Vulnerability (CVE-2024-21211)