Description
WordPress Plugin SAM Pro (Free Edition) is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin SAM Pro (Free Edition) version 1.9.6.67 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.9.7.69 or latest
References
Related Vulnerabilities
WordPress Plugin Comment Extra Fields 'cef-upload.php' Arbitrary File Upload (1.7)
WordPress Plugin MyLiveChat-Free Live Chat Plugin for WordPress Cross-Site Scripting (2.0.1)
WordPress Plugin WP Statistics SQL Injection (13.2.8)
WordPress Plugin WPCB Cross-Site Scripting (2.4.8)
WordPress Plugin Simple Job Board Cross-Site Scripting (2.9.4)