Description
WordPress Plugin Light Post is prone to a remote file include vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible. WordPress Plugin Light Post version 1.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5 or latest
References
Related Vulnerabilities
WordPress Plugin WP Domain Redirect SQL Injection (1.0)
concrete5 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-5107)
WordPress Plugin Universal Star Rating Unspecified Vulnerability (1.10.3)
WordPress Plugin WooCommerce Export Orders and More Cross-Site Scripting (2.0.10)
WordPress Plugin JobSearch WP Job Board Cross-Site Scripting (1.5.2)