Description
WordPress Plugin Landing Page Builder-Lead Page-Optin Page-Squeeze Page-WordPress Landing Pages is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Landing Page Builder-Lead Page-Optin Page-Squeeze Page-WordPress Landing Pages version 1.4.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.4 or latest
References
Related Vulnerabilities
WordPress Other Vulnerability (CVE-2005-2612)
WordPress Plugin PayPlus Payment Gateway SQL Injection (7.0.7)
Jboss EAP Improper Input Validation Vulnerability (CVE-2016-3110)
WordPress Plugin Spreadsheet (wpSS) SQL Injection (0.62)
WordPress Plugin Discount Rules for WooCommerce Security Bypass (2.2.0)