Description
WordPress Plugin WP Rocket is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WP Rocket version 2.10.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.10.4 or latest
References
Related Vulnerabilities
WordPress Plugin WPFront Scroll Top Cross-Site Scripting (2.0.6.07225)
WordPress Plugin Comment Highlighter SQL Injection (0.13)
WordPress Plugin WP Construction Mode Cross-Site Request Forgery (3.31)
WordPress Plugin Login as User or Customer Privilege Escalation (3.2)
WordPress Plugin Drag & Drop File Uploader 'dnd-upload.php' Arbitrary File Upload (0.1)