RULE(RULE ID:330131)

Rule General Information
Release Date: 2020-05-25
Rule Name: WordPress Plugin Local File Inclusion Vulnerability (CVE-2018-16299)
Severity:
CVE ID:
Rule Protection Details
Description: The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux
Reference: ExploitDB:45439
http://seclists.org/fulldisclosure/2018/Sep/33
https://github.com/julianburr/wp-plugin-localizemypost/issues/1
https://packetstormsecurity.com/files/149433/WordPress-Localize-My-Post-1.0-Local-File-Inclusion.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://github.com/julianburr/wp-plugin-localizemypost