Description
WordPress Plugin VendorFuel is prone to a local file overwrite vulnerability. Attackers can possibly exploit this issue to rewrite the contents of a .css file. This can be coupled with other existing vulnerabilities to affect the vulnerable application in various ways. WordPress Plugin VendorFuel version 1.3.1 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin WonderPlugin Audio Player Multiple Vulnerabilities (2.0)
Caddy Web Server URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29718)
MySQL CVE-2020-2926 Vulnerability (CVE-2020-2926)
Ruby on Rails Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-0447)