Description
WordPress Plugin JetWidgets for Elementor and WooCommerce is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin JetWidgets for Elementor and WooCommerce version 1.1.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.8 or latest
References
Related Vulnerabilities
WordPress 4.2.x Arbitrary File Deletion Vulnerability (4.2 - 4.2.20)
Apache HTTP Server Other Vulnerability (CVE-2001-0731)
MySQL CVE-2019-2743 Vulnerability (CVE-2019-2743)
WordPress Plugin WP Custom Fields Search Cross-Site Scripting (1.2.34)
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-23498)