Description
WordPress Plugin A Page Flip Book is prone to a local file include vulnerability because it fails to sufficiently sanitize user-supplied input. An attacker can exploit this vulnerability to view files and execute local scripts in the context of the web server process; this may aid in launching further attacks. WordPress Plugin A Page Flip Book version 2.3 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
http://ceriksen.com/2012/07/10/wordpress-a-page-flip-book-plugin-local-file-inclusion-vulnerability/
Related Vulnerabilities
WordPress Plugin WP BASE Booking of Appointments, Services and Events PHP Object Injection (3.5.0)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-3092)
WordPress Plugin All-in-One Event Calendar Cross-Site Scripting (2.5.38)
Drupal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-13662)