Description
WordPress Plugin WordPress PDF Light Viewer is prone to a command injection vulnerability because it fails to properly validate user-supplied input. An attacker can exploit this issue to execute arbitrary commands within the context of the vulnerable application. WordPress Plugin WordPress PDF Light Viewer version 1.4.11 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.12 or latest
References
Related Vulnerabilities
MySQL CVE-2016-3459 Vulnerability (CVE-2016-3459)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0125)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (4.1.9)
WordPress Plugin Contact Form by ContactMe.com Cross-Site Scripting (2.3)