Description
WordPress Plugin SG Optimizer is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin SG Optimizer version 5.0.12 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.0.13 or latest
References
https://blog.sucuri.net/2019/03/vulnerability-disclosure-siteground-optimizer-caldera-forms.html
https://plugins.svn.wordpress.org/sg-cachepress/trunk/readme.txt
Related Vulnerabilities
Joomla! Core 3.9.x Information Disclosure (3.9.0 - 3.9.22)
Drupal Core 4.7.x Security Bypass (4.7.0 - 4.7.7)
WordPress Plugin Form Vibes-Database Manager for Forms Unspecified Vulnerability (1.4.2)
WordPress Plugin Thank You Counter Button Cross-Site Scripting (1.8.2)
WordPress Plugin Elementor Website Builder Cross-Site Scripting (3.4.7)