Description
WordPress Plugin WP Cost Estimation & Payment Forms Builder is prone to a directory traversal vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WP Cost Estimation & Payment Forms Builder version 9.659 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 9.660 or latest
References
Related Vulnerabilities
WordPress Plugin WP Frontend Profile Security Bypass (1.2.1)
WordPress 'admin-ajax.php' SQL Injection Vulnerability (2.1.3 - 2.1.3)
WordPress Plugin Radio Buttons for Taxonomies Cross-Site Request Forgery (2.0.5)
Joomla! Core 1.6.x Information Disclosure (1.6.0 - 1.6.3)
WordPress Plugin Woo Import Export Arbitrary File Deletion (1.0)