Description
WordPress Plugin IMDb Profile Widget is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin IMDb Profile Widget version 1.0.8 is vulnerable; other versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
PostgreSQL Other Vulnerability (CVE-2007-3279)
Django Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-4534)
PHP multipart/form-data denial of service
WordPress Plugin AccessAlly Information Disclosure (3.5.6)
WordPress Plugin Complete Gallery Manager for WordPress Arbitrary File Upload (3.3.3)