Description
Acunetix uploaded a ZIP file containing a symlink to /etc/passwd. It looks like that web application processed this file and returned the contents of /etc/passwd in response.
Remediation
The web application should filter symlinks included inside ZIP files.
References
Related Vulnerabilities
WordPress Plugin IP Blacklist Cloud Arbitrary File Disclosure (3.42)
WordPress 5.2.x Multiple Vulnerabilities (5.2 - 5.2.9)
WordPress Plugin WP Activity Log Information Disclosure (3.1.1)
WordPress Plugin Thumbnail carousel slider Arbitrary File Upload (1.0)
WordPress Plugin NextGEN Gallery-WordPress Gallery Arbitrary File Upload (2.1.10)