Description
WordPress Plugin PictPress is prone to multiple local file include vulnerabilities because it fails to properly sanitize user-supplied input. Exploiting these issues may allow an unauthorized user to view files and execute local scripts. WordPress Plugin PictPress version 0.91 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
http://www.securityfocus.com/bid/26743/exploit
http://www.exploit-db.com/exploits/4695/
http://packetstormsecurity.com/files/view/61555/wppict-disclose.txt
Related Vulnerabilities
WordPress Plugin Disable Image Right Click Cross-Site Scripting (1.0)
WordPress Plugin Storefront Footer Text Cross-Site Scripting (1.0.1)
WordPress Plugin Admin Bar User Switching Cross-Site Scripting (1.0.4)
concrete5 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-24986)
WordPress Plugin Login Security Solution Multiple Unspecified Vulnerabilities (0.50.0)