Description
WordPress Plugin Add From Server is prone to a directory traversal vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Add From Server version 3.3.3 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
MySQL Other Vulnerability (CVE-2006-3081)
MySQL CVE-2019-2730 Vulnerability (CVE-2019-2730)
WordPress Plugin Sliding Recent Posts Cross-Site Request Forgery (1.0)
Apache Tomcat Improper Resource Shutdown or Release Vulnerability (CVE-2022-25762)
phpBB Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-11767)