Description
WordPress Plugin Simple History is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Simple History version 2.7.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7.5 or latest
References
Related Vulnerabilities
WordPress Plugin Profile Extra Fields by BestWebSoft Cross-Site Scripting (1.0.7)
WordPress Plugin Lazyest Backup 'xml_or_all' Parameter Cross-Site Scripting (0.2.1)
WordPress Plugin Advanced Custom Fields Cross-Site Scripting (5.8.11)
WordPress Plugin WordPress Backup to Dropbox Information Disclosure (4.7.1)
WordPress Plugin Media File Renamer-Auto & Manual Rename Cross-Site Scripting (1.7.0)