Description
WordPress Plugin ApplyOnline-Application Form Builder and Manager is prone to an arbitrary file disclosure vulnerability because it fails to properly verify user-supplied input. An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in launching further attacks. WordPress Plugin ApplyOnline-Application Form Builder and Manager version 1.9.92 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.9.96 or latest
References
Related Vulnerabilities
Microsoft SQL Server Other Vulnerability (CVE-2000-1081)
WordPress Plugin Slimstat Analytics Multiple Vulnerabilities (5.0.9)
WordPress Plugin Simple Download Button Shortcode 'file' Parameter Information Disclosure (1.0)
WordPress Plugin Age Verification 'redirect_to' Parameter URI Redirection (0.4)