Description
WordPress Plugin Woocommerce-Recent Purchases is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Woocommerce-Recent Purchases version 1.0.1 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin WooCommerce Possible Remote Code Execution (3.4.5)
MediaWiki Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2021-36125)
WordPress Plugin Calendar Multiple Cross-Site Scripting Vulnerabilities (1.2.1)
Joomla Use of Insufficiently Random Values Vulnerability (CVE-2012-1562)
WordPress Plugin Mingle Forum Multiple Cross-Site Scripting Vulnerabilities (1.0.33)