Description
WordPress Plugin Ajax Pagination (twitter Style) is prone to a local file inclusion vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Ajax Pagination (twitter Style) version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
http://www.exploit-db.com/exploits/32622/
http://seclists.org/fulldisclosure/2014/Mar/398
http://packetstormsecurity.com/files/125929/Ajax-Pagination-1.1-Local-File-Inclusion.html
Related Vulnerabilities
WordPress Plugin Podcast Subscribe Buttons Cross-Site Scripting (1.4.1)
Oracle Database Server CVE-2010-2407 Vulnerability (CVE-2010-2407)
WordPress Plugin NextGEN Gallery-WordPress Gallery Unspecified Vulnerability (2.0.77.3)
Drupal Improper Input Validation Vulnerability (CVE-2012-5653)
Atlassian Jira Improper Authentication Vulnerability (CVE-2019-8443)