The PixelYourSite WordPress plugin before 11.1.2 does...
Low severity
Unreviewed
Published
Oct 24, 2025
to the GitHub Advisory Database
•
Updated Oct 24, 2025
Description
Published by the National Vulnerability Database
Oct 24, 2025
Published to the GitHub Advisory Database
Oct 24, 2025
Last updated
Oct 24, 2025
The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks
References