Description
WordPress Plugin Advanced Classifieds & Directory Pro is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Advanced Classifieds & Directory Pro version 3.1.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.1 or latest
References
Related Vulnerabilities
Varnish Cache Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0345)
WordPress Plugin Slimstat Analytics SQL Injection (3.9.5)
Oracle Database Server CVE-2009-3413 Vulnerability (CVE-2009-3413)
IBMHttpServer Other Vulnerability (CVE-2001-0122)
WordPress Improper Input Validation Vulnerability (CVE-2018-20152)