Description
WordPress Plugin jRSS Widget is prone to a directory traversal vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin jRSS Widget version 1.1.1 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 1.2 or latest
References
Related Vulnerabilities
WordPress Plugin Admin PHP Eval Unspecified Vulnerability (1.0)
concrete5 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-24986)
WordPress Plugin Easy Forms for Mailchimp PHP Code Injection (6.5.2)
WordPress Plugin Site Offline Or Coming Soon Or Maintenance Mode Cross-Site Request Forgery (1.4.3)