Description
WordPress Plugin VendorFuel is prone to a local file overwrite vulnerability. Attackers can possibly exploit this issue to rewrite the contents of a .css file. This can be coupled with other existing vulnerabilities to affect the vulnerable application in various ways. WordPress Plugin VendorFuel version 1.3.1 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin LayerSlider Multiple Vulnerabilities (6.2.0)
WordPress Plugin Simple Membership Security Bypass (3.8.5)
Oracle Application Server Other Vulnerability (CVE-2002-0562)
Python Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-3426)
WordPress Plugin myghpay WooCommerce Payment Gateway Cross-Site Scripting (3.0)