Description
WordPress Plugin Events Calendar for Google is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Events Calendar for Google version 2.1.0 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable and remove the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Advanced Classifieds & Directory Pro Cross-Site Scripting (1.7.5)
MyBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-4624)
Internet Information Services Other Vulnerability (CVE-2001-0506)
GlassFish Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-3239)