- WordPress Plugin wp-FileManager is prone to an arbitrary file disclosure vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in launching further attacks. WordPress Plugin wp-FileManager version 1.3.0 is vulnerable; other versions may also be affected.
- Update to plugin version 1.4.0 or latest
- WordPress Plugin WordPress Catalog Multiple Cross-Site Scripting and SQL Injection Vulnerabilities (1.4.6)
- WordPress Plugin Link Library 'searchll' Parameter SQL Injection (5.2.1)
- WordPress Plugin Aspose Cloud eBook Generator Arbitrary File Download (1.0)
- WordPress Plugin Fast Secure Contact Form Remote Code Execution (4.0.44)
- WordPress Plugin HB AUDIO GALLERY LITE Arbitrary File Download (1.0.0)