Description
WordPress Plugin WP Docs is prone to multiple vulnerabilities, including PHP object injection and cross-site request forgery vulnerabilities. A successful exploit may allow an attacker to execute arbitrary PHP code within the context of the affected webserver process or to perform certain administrative actions; other attacks are also possible. WordPress Plugin WP Docs version 1.1.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.8 or latest
References
Related Vulnerabilities
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-2891)
WordPress 5.4.x Multiple Vulnerabilities (5.4 - 5.4.1)
WordPress Plugin GiveWP-Donation and Fundraising Platform Cross-Site Scripting (2.9.7)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2022-31780)
WordPress Plugin Responsive Lightbox by dFactory Cross-Site Scripting (1.4.11)