Description
The WordPress plugin Slider Revolution was vulnerable to an arbitrary file disclosure vulnerability that allows an attacker to download any file from the server. This vulnerability is/was actively exploited in the wild.
Remediation
Upgrade to the latest version of the plugin.
References
Related Vulnerabilities
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.7)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1000862)
WordPress Plugin Slider Revolution Responsive Local File Inclusion (4.1.4)
Unauthenticated Arbitrary File Read vulnerability in VMware vCenter
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-5498)