Description
WordPress Plugin WP Payeezy Pay is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WP Payeezy Pay version 2.97 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 2.98 or latest
References
Related Vulnerabilities
Microsoft SQL Server Other Vulnerability (CVE-2000-1081)
PHP Resource Management Errors Vulnerability (CVE-2007-4660)
PHP Other Vulnerability (CVE-2015-4601)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-7061)
ownCloud Improper Input Validation Vulnerability (CVE-2013-1939)