Description
WordPress Plugin Ruben Boelinger WP-Table is prone to multiple remote file include vulnerabilities because it fails to sufficiently sanitize user-supplied data. Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible. WordPress Plugin Ruben Boelinger WP-Table version 1.43 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 1.44 or latest
References
http://www.securityfocus.com/bid/23737/exploit
http://www.securityfocus.com/archive/1/467363
Related Vulnerabilities
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2016-8612)
Apache Tomcat version older than 7.0.21
Jboss EAP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-0248)
WordPress Plugin Coming Soon & Maintenance Mode Page PHP Object Injection (1.42)
WordPress Plugin Coming soon and Maintenance mode Unspecified Vulnerability (3.5.4)