Description
WordPress Plugin Woocommerce-Recent Purchases is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Woocommerce-Recent Purchases version 1.0.1 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
Jenkins Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3666)
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2017-3169)
Drupal Core 7.x Denial of Service (7.0 - 7.30)
Oracle Database Server CVE-2015-2655 Vulnerability (CVE-2015-2655)
Oracle Database Server CVE-2012-1751 Vulnerability (CVE-2012-1751)