Description
WordPress Plugin Insert Pages is prone to a directory traversal vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Insert Pages version 3.2.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.4 or latest
References
https://wordpress.org/support/topic/insert-pages-has-been-removed-from-wordpress-org/
https://plugins.svn.wordpress.org/insert-pages/trunk/readme.txt
Related Vulnerabilities
WordPress 4.9.x Prototype Pollution (4.9 - 4.9.19)
Drupal Core 8.9.x Arbitrary File Overwrite (8.9.0 - 8.9.12)
WordPress Plugin Relevanssi-A Better Search SQL Injection (3.2)
WordPress Plugin User Access Manager Cross-Site Scripting (1.2.6.7)
WordPress Plugin Advanced Custom Fields:reCAPTCHA Field Security Bypass (1.1.1)