Description
WordPress Plugin History Collection is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin History Collection version 1.1.1 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Portfolio-WordPress Portfolio Cross-Site Scripting (2.8.10)
PrestaShop Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-19594)
WordPress Plugin Enhanced Plugin Admin Cross-Site Scripting (1.15)
PostgreSQL Missing Encryption of Sensitive Data Vulnerability (CVE-2017-7485)
WordPress Plugin Theme Blvd Shortcodes Multiple Security Bypass Vulnerabilities (1.5.2)