Description
WordPress Plugin CIP4 Folder Download Widget is prone to a local file inclusion vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin CIP4 Folder Download Widget version 1.10 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Gallery by BestWebSoft 'php.php' Arbitrary File Upload (3.06)
WordPress Missing Authentication for Critical Function Vulnerability (CVE-2020-11028)
Django Resource Management Errors Vulnerability (CVE-2015-5963)
WordPress Plugin WP Editor Arbitrary File Upload (1.2.5.3)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1130)