Description
WordPress Plugin Ajax Store Locator is prone to a directory traversal vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Ajax Store Locator version 1.2.0 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
Jboss EAP Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2021-3642)
LimeSurvey Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-16177)
WordPress Plugin Gwolle Guestbook Remote File Inclusion (1.5.3)
MySQL CVE-2012-3144 Vulnerability (CVE-2012-3144)
Oracle HTTP Server NULL Pointer Dereference Vulnerability (CVE-2020-1971)