Description
WordPress Plugin Woocommerce-Recent Purchases is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Woocommerce-Recent Purchases version 1.0.1 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
Caddy Web Server Authentication Bypass by Spoofing Vulnerability (CVE-2023-50463)
Joomla! Core Security Bypass (2.5.0 - 3.9.27)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-31549)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-1810)