Description
WordPress Plugin Sniplets is prone to multiple input validation vulnerabilities because the application fails to sanitize user-supplied input. These issues include multiple cross-site scripting vulnerabilities, a remote file include vulnerability, and a remote command execution vulnerability. A successful exploit may allow an attacker to compromise the application, steal cookie-based authentication credentials, and execute arbitrary code and commands within the context of the webserver process. WordPress Plugin Sniplets version 1.2.2 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 1.2.3 or latest
References
http://www.exploit-db.com/exploits/5194/
http://www.securityfocus.com/bid/27985/exploit
http://www.securityfocus.com/archive/1/488734
http://packetstormsecurity.com/files/view/64011/wordpresssniplet-rfixssexec.txt
Related Vulnerabilities
MySQL CVE-2015-4833 Vulnerability (CVE-2015-4833)
WordPress Plugin Yasr-Yet Another Stars Rating PHP Object Injection (1.8.6)
Oracle Database Server CVE-2015-2585 Vulnerability (CVE-2015-2585)
MySQL CVE-2019-2531 Vulnerability (CVE-2019-2531)
SugarCRM Improper Input Validation Vulnerability (CVE-2011-0745)