Description
WordPress Plugin SL User Create is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin SL User Create version 0.2.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.2.5 or latest
References
Related Vulnerabilities
WordPress Plugin Hungred Post Thumbnail 'hpt_file_upload.php' Arbitrary File Upload (2.1.9)
WordPress Plugin Team Members Cross-Site Scripting (5.0.3)
WordPress 5.6.x Multiple Vulnerabilities (5.6 - 5.6.10)
WordPress Plugin GeoDirectory Location Manager Multiple SQL Injection Vulnerabilities (2.1.0.9)
WordPress Plugin Direct Download for Woocommerce Arbitrary File Download (1.15)