Description
WordPress Plugin Sina Extension for Elementor is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Sina Extension for Elementor version 2.2.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.1 or latest
References
Related Vulnerabilities
WordPress Plugin WordPress Custom Global Variable Unspecified Vulnerability (3.0.0)
WordPress Plugin NextMove Lite-Thank You Page for WooCommerce Security Bypass (2.17.0)
Magento Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-7932)
WordPress Plugin Image Gallery with Slideshow 'upload-file.php' Arbitrary File Upload (1.5)
Oracle Application Server Other Vulnerability (CVE-2007-0282)