Description
WordPress Plugin WordPress PDF Light Viewer is prone to a command injection vulnerability because it fails to properly validate user-supplied input. An attacker can exploit this issue to execute arbitrary commands within the context of the vulnerable application. WordPress Plugin WordPress PDF Light Viewer version 1.4.11 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.12 or latest
References
Related Vulnerabilities
Joomla! Core 3.x.x Security Bypass (3.7.0 - 3.8.11)
WordPress Plugin Add Custom Link to WordPress Admin Bar Cross-Site Scripting (1.0)
WordPress 3.8.x Cross-Site Request Forgery (3.8 - 3.8.28)
WordPress Plugin All-in-One WP Migration Security Bypass (7.14)
WordPress Plugin Good LMS-Learning Management System SQL Injection (2.1.4)