Description
WordPress Plugin Flamingo is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary code within the context of the affected webserver process; this may result in total compromise of the web server. WordPress Plugin Flamingo version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.1 or latest
References
Related Vulnerabilities
WordPress Plugin PHP Event Calendar for WordPress Arbitrary File Upload (1.6)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3092)
phpMyFAQ 7PK - Security Features Vulnerability (CVE-2014-6050)
WordPress Plugin Dynamic Widgets Multiple Cross-Site Scripting Vulnerabilities (1.5.10)
PHP Resource Management Errors Vulnerability (CVE-2011-3267)