Description
WordPress Plugin Startklar Elementor Addons is prone to a directory traversal vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Startklar Elementor Addons version 1.7.15 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
TYPO3 Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-26229)
GlassFish CVE-2016-5528 Vulnerability (CVE-2016-5528)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-2922)
WordPress Plugin Rezgo Online Booking Cross-Site Scripting (1.8.6)