Description
WordPress Plugin Add From Server is prone to a directory traversal vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Add From Server version 3.3.3 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3226)
MySQL CVE-2019-2537 Vulnerability (CVE-2019-2537)
Squid Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-18677)
WordPress Plugin Polls CP Unspecified Vulnerability (1.0.17)
Atlassian Jira Missing Authorization Vulnerability (CVE-2020-14185)