Description
WordPress Plugin Social Discussions is prone to a remote file include vulnerability and an information disclosure vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting these issues could allow an attacker to compromise the application and the underlying system or to obtain sensitive information which may help in launching further attacks. WordPress Plugin Social Discussions version 6.1.1 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 6.1.2 or latest
References
http://www.securityfocus.com/bid/56091/exploit
http://www.exploit-db.com/exploits/22158/
Related Vulnerabilities
WordPress Plugin Custom Global Variables Cross-Site Scripting (1.0.5)
Python Protection Mechanism Failure Vulnerability (CVE-2016-0772)
Ruby Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-16255)
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud Security Bypass (3.9.2)