Description
WordPress Plugin WP Post Popup is prone to a directory traversal vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WP Post Popup version 2.1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.1.2 or latest
References
Related Vulnerabilities
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1000395)
WordPress Plugin Olimometer SQL Injection (2.56)
WordPress Plugin Video Conferencing with Zoom Cross-Site Scripting (4.0.9)
Envoy Proxy Improper Certificate Validation Vulnerability (CVE-2022-21657)
e107 Credentials Management Errors Vulnerability (CVE-2013-7305)