Description
WordPress Plugin WP Image Zoom is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WP Image Zoom version 1.46 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.47 or latest
References
Related Vulnerabilities
WordPress Plugin 123devis-affiliation Cross-Site Scripting (1.0.4)
WordPress Plugin Custom css-js-php Cross-Site Request Forgery (2.0.7)
PostgreSQL Improper Control of Dynamically-Managed Code Resources Vulnerability (CVE-2022-2625)
WordPress Plugin WPML (WordPress Multilingual) Cross-Site Scripting (3.2.6)