Description
A composer.lock file was discovered in this directory. Composer is a tool for dependency management in PHP. It allows you to declare the libraries your project depends on and it will manage (install/update) them for you. After installing the dependencies, Composer writes the list of the exact versions it installed into a composer.lock file. This locks the project to those specific versions.
Acunetix analyzed all the project dependencies listed in the composer.lock file and found one or more project dependencies with known vulnerabilities. It's recommended to upgrade all the vulnerable packages to the latest versions.
Remediation
Upgrade each vulnerable package to the latest version.
References
Related Vulnerabilities
WordPress Plugin Sports Rankings and Lists Cross-Site Scripting (3.5)
MySQL CVE-2015-4800 Vulnerability (CVE-2015-4800)
MySQL CVE-2017-10283 Vulnerability (CVE-2017-10283)
Varnish Cache Integer Overflow or Wraparound Vulnerability (CVE-2017-12425)
WordPress Plugin Baggage Freight Shipping Australia Arbitrary File Upload (0.1.0)