Description
WordPress Plugin YARPP-Yet Another Related Posts is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin YARPP-Yet Another Related Posts version 5.30.3 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Insert Pages Cross-Site Scripting (3.7.4)
Artifactory Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-46687)
Drupal 7PK - Security Features Vulnerability (CVE-2016-3163)
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6146)
OpenSSL Improper Input Validation Vulnerability (CVE-2009-3245)