Description
WordPress Plugin Super Refer A Friend is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Super Refer A Friend version 1.0 is vulnerable.
Remediation
Edit the source code to ensure that errors containing sensitive information aren't displayed to the end user or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Audio 'showfile' Parameter Cross-Site Scripting (0.5.1)
WordPress Plugin Easy Author Image Information Disclosure (1.5)
IBM WebSEAL Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-4699)
phpMyAdmin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-1149)