Description
WordPress Plugin PictPress is prone to multiple local file include vulnerabilities because it fails to properly sanitize user-supplied input. Exploiting these issues may allow an unauthorized user to view files and execute local scripts. WordPress Plugin PictPress version 0.91 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
http://www.securityfocus.com/bid/26743/exploit
http://www.exploit-db.com/exploits/4695/
http://packetstormsecurity.com/files/view/61555/wppict-disclose.txt
Related Vulnerabilities
WordPress Plugin Events Shortcodes For The Events Calendar Security Bypass (1.9.4)
WordPress Plugin Advanced Classifieds & Directory Pro Unspecified Vulnerability (1.6.5)
WordPress Plugin MailChimp for WooCommerce Local File Inclusion (2.1.1)
WordPress Plugin WP Fastest Cache Directory Traversal (0.8.9.5)
TYPO3 Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4320)