Description
WordPress Plugin Redirection is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Redirection version 2.7.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.8 or latest
References
https://advisories.dxw.com/advisories/ace-file-inclusion-redirection/
https://packetstormsecurity.com/files/148167/WordPress-Redirection-2.7.3-Remote-File-Inclusion.html