Description
WordPress Plugin Aspose Importer & Exporter is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Aspose Importer & Exporter versions 2.0 and prior are vulnerable.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2021-20502)
WordPress Plugin Placemarks Cross-Site Scripting (2.0.0)
WordPress Plugin WP iCommerce-the first interactive ecommerce for wordpress SQL Injection (1.1.1)
Python Uncontrolled Search Path Element Vulnerability (CVE-2017-20052)