Description
WordPress Plugin VendorFuel is prone to a local file overwrite vulnerability. Attackers can possibly exploit this issue to rewrite the contents of a .css file. This can be coupled with other existing vulnerabilities to affect the vulnerable application in various ways. WordPress Plugin VendorFuel version 1.3.1 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
XWiki Incorrect Use of Privileged APIs Vulnerability (CVE-2022-24821)
Oracle HTTP Server CVE-2018-2561 Vulnerability (CVE-2018-2561)
WordPress Plugin DB Toolkit 'uploadify.php' Arbitrary File Upload (0.1.10)
Drupal Core 4.7.x Denial of Service (4.7.0 - 4.7.4)
phpMyAdmin Improper Input Validation Vulnerability (CVE-2011-0986)