Description
WordPress Plugin VendorFuel is prone to a local file overwrite vulnerability. Attackers can possibly exploit this issue to rewrite the contents of a .css file. This can be coupled with other existing vulnerabilities to affect the vulnerable application in various ways. WordPress Plugin VendorFuel version 1.3.1 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
OpenSSL Numeric Errors Vulnerability (CVE-2012-2131)
WordPress Plugin Light Messages Cross-Site Request Forgery (1.0)
Oracle JRE CVE-2019-2975 Vulnerability (CVE-2019-2975)
WordPress Plugin Newsletters Multiple Vulnerabilities (4.6.5.3)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-3325)