Description
WordPress Plugin Posts in Page is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Posts in Page version 1.2.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.0 or latest
References
Related Vulnerabilities
WordPress Plugin Facebook Promotion Generator for WordPress 'fbActivate.php' SQL Injection (1.3.3)
WordPress Plugin SVG Support Cross-Site Scripting (2.5.1)
WordPress Plugin MouseWheel Smooth Scroll Cross-Site Request Forgery (5.6)
WordPress Plugin BookX Local File Inclusion (1.7)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2008-1672)