Description
The WordPress plugin Slider Revolution was vulnerable to an arbitrary file disclosure vulnerability that allows an attacker to download any file from the server. This vulnerability is/was actively exploited in the wild.
Remediation
Upgrade to the latest version of the plugin.
References
Related Vulnerabilities
WordPress Plugin Activity Log Information Disclosure (2.2.12)
WordPress Plugin Annonces 'abspath' Parameter Remote File Include (1.2.0.0)
IBM WebSEAL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3045)
WordPress Plugin Yoast SEO Information Disclosure (3.2.4)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5508)