Description
WordPress Plugin News Element Elementor Blog Magazine is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin News Element Elementor Blog Magazine version 1.0.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.6 or latest
References
Related Vulnerabilities
Oracle JRE CVE-2014-0458 Vulnerability (CVE-2014-0458)
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33327)
WordPress Plugin External Links-nofollow, noopener & new window Cross-Site Scripting (2.55)
Oracle Database Server CVE-2007-5515 Vulnerability (CVE-2007-5515)
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2018-1000861)