Description
WordPress Plugin SG Optimizer is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin SG Optimizer version 5.0.12 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.0.13 or latest
References
https://blog.sucuri.net/2019/03/vulnerability-disclosure-siteground-optimizer-caldera-forms.html
https://plugins.svn.wordpress.org/sg-cachepress/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease SQL Injection (4.1.4)
Ruby Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-10933)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4283)
Vanilla Forums Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4954)