Description
WordPress Plugin Vmax Project Manager is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Vmax Project Manager version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-3230)
WordPress Plugin OneLogin SAML SSO Unspecified Vulnerability (2.1.8)
WordPress Plugin Ultimate TinyMCE Multiple Unspecified Vulnerabilities (5.0)
Next.js CVE-2022-21721 Vulnerability (CVE-2022-21721)
WordPress Plugin Influencer Marketing & Press Release System Cross-Site Scripting (2.2)