load_template of the file includes/core/class-shortcodes.php of the component Template Handler. Executing a manipulation of the argument tpl can lead to pathname traversal.
The identification of this vulnerability is CVE-2022-3966. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
Intelligence View
SOCIAL SHARE CARD GENERATOR