The web application uses Total.js framework. Total.js before 3.2.4 has a directroy traversal vulnerability. An attacker can craft a request that accesses potentially sensitive information on the server, that may lead to takeover of the server.
Upgrade to the latest version of Total.js
Related Vulnerabilities
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Directory Traversal (1.3.33)
WordPress Plugin WP Cost Estimation & Payment Forms Builder Directory Traversal (9.659)
WordPress 4.5.3 Directory Traversal Vulnerability (4.5.3)
WordPress Plugin Booking Ultra Pro Appointments Booking Calendar Local File Inclusion (1.1.13)
WordPress Plugin wp-FileManager Arbitrary File Disclosure (1.3.0)