Description
WordPress Plugin Events Calendar for Google is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Events Calendar for Google version 2.1.0 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable and remove the plugin until a fix is available
References
Related Vulnerabilities
MongoDb Reachable Assertion Vulnerability (CVE-2021-32037)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-32472)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.15.22)
Oracle Application Server CVE-2008-7236 Vulnerability (CVE-2008-7236)