WordPress TheCartPress Plugin 'tcp_class_path' Parameter Remote File Include Vulnerability

Summary
TheCartPress plug-in for WordPress is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user- supplied input. Exploiting this issue could allow an attacker to compromise the application and the underlying system other attacks are also possible. TheCartPress 1.1.1 is vulnerable other versions may also be affected.
References