An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in queryphp://filter/resource in the jsmol.php query string. This can also be used for SSRF.
Publication date: Wed, 26 Dec 2018 03:29:00 +0000