Description
WordPress Plugin Duplicator-WordPress Migration is prone to an arbitrary file disclosure vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in launching further attacks. WordPress Plugin Duplicator-WordPress Migration version 0.3.0 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
Related Vulnerabilities
WordPress Plugin Pinterest by BestWebSoft Cross-Site Scripting (1.0.4)
WordPress Plugin Mailtree Log Mail Cross-Site Scripting (1.0.0)
WordPress Plugin Tabs-Responsive Tabs with WooCommerce Product Tab Extension Security Bypass (3.5.4)
Oracle Database Server Improper Input Validation Vulnerability (CVE-2020-1953)