Description
WordPress Plugin Service Finder-Provider and Business Listing is prone to a local file disclosure vulnerability because it fails to adequately validate user-supplied input. Exploiting this vulnerability could allow an attacker to obtain potentially sensitive information from local files on computers running the vulnerable application; this may aid in further attacks. WordPress Plugin Service Finder-Provider and Business Listing version 3.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2 or latest
References
Related Vulnerabilities
WordPress Plugin Debug Bar Unspecified Vulnerability (0.8)
OpenVPN AS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-2061)
WordPress Plugin Current Book Cross-Site Scripting (1.0.1)
WordPress Plugin Ceceppa Multilingua Unspecified Vulnerability (1.5.3)
Magento Insufficient Verification of Data Authenticity Vulnerability (CVE-2019-8112)