Description
WordPress Plugin Forums is prone to an arbitrary file disclosure vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in launching further attacks. WordPress Plugin Forums version 1.4.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.4 or latest
References
Related Vulnerabilities
MediaWiki Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1190)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-11620)
MySQL CVE-2022-21323 Vulnerability (CVE-2022-21323)
WordPress Improper Authentication Vulnerability (CVE-2022-43504)
WordPress Plugin Event Single Page Templates Addon For The Events Calendar Security Bypass (1.5)