Description
WordPress Plugin WP Rocket is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WP Rocket version 2.10.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.10.4 or latest
References
Related Vulnerabilities
WordPress Plugin Classified Listing Pro & Directory Cross-Site Scripting (2.0.19)
WordPress Plugin RocketTheme RokBox 'jwplayer.swf' Cross-Site Scripting (2.11)
WordPress Plugin BuddyPress Unspecified Vulnerability (2.6.0)
WordPress Plugin wp superb Slideshow Information Disclosure (2.4)
WordPress Plugin Custom Background 'uploadify.php' Arbitrary File Upload (1.01)