Description
WordPress Plugin IMDb Profile Widget is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin IMDb Profile Widget version 1.0.8 is vulnerable; other versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4279)
WordPress Plugin Elementor Website Builder Cross-Site Scripting (2.9.13)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1862)
WordPress 4.8.x Arbitrary File Deletion Vulnerability (4.8 - 4.8.6)
WordPress Plugin CoolClock-a Javascript Analog Clock Cross-Site Scripting (4.3.4)