Description
WordPress Plugin WordPress PDF Light Viewer is prone to a command injection vulnerability because it fails to properly validate user-supplied input. An attacker can exploit this issue to execute arbitrary commands within the context of the vulnerable application. WordPress Plugin WordPress PDF Light Viewer version 1.4.11 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.12 or latest
References
Related Vulnerabilities
Atlassian Jira Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-8451)
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6146)
WordPress Plugin User Login Log Cross-Site Scripting (2.2.2)
WordPress Plugin WP Custom Pages 'url' Parameter Local File Disclosure (0.5.0.1)
WordPress Plugin Username Changer Multiple Vulnerabilities (1.4)