Description
WordPress Plugin WP Image Zoom is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WP Image Zoom version 1.46 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.47 or latest
References
Related Vulnerabilities
WordPress Plugin Page Builder by SiteOrigin Cross-Site Scripting (2.0.4)
WordPress Plugin WP Advanced Comment Cross-Site Scripting (0.10)
WordPress Plugin Poll, Survey, Questionnaire and Voting system SQL Injection (1.2.4)
WordPress Plugin Tera Charts Cross-Site Scripting (1.0)
WordPress Plugin Google Analytics MU Cross-Site Request Forgery (2.3.1)