Description
WordPress Plugin Payment Gateways Caller for WP e-Commerce is prone to a local file inclusion vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Payment Gateways Caller for WP e-Commerce version 0.1 is vulnerable.
Remediation
Update to plugin version 0.1.1 or latest
References
Related Vulnerabilities
WordPress Plugin Profile Builder-User Profile & User Registration Forms Cross-Site Scripting (2.4.1)
Drupal Core 4.7.x Cross-Site Request Forgery (4.7.0 - 4.7.3)
WordPress Plugin Easy Forms for MailChimp Cross-Site Scripting (6.1.2)
WordPress Plugin Shopping Cart & eCommerce Store Arbitrary File Upload (3.0.8)
WordPress Plugin Recipe Card Blocks for Gutenberg & Elementor Cross-Site Scripting (2.8.0)