Description
WordPress Plugin Social Discussions is prone to a remote file include vulnerability and an information disclosure vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting these issues could allow an attacker to compromise the application and the underlying system or to obtain sensitive information which may help in launching further attacks. WordPress Plugin Social Discussions version 6.1.1 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 6.1.2 or latest
References
http://www.securityfocus.com/bid/56091/exploit
http://www.exploit-db.com/exploits/22158/
Related Vulnerabilities
WordPress Plugin eHive Account Details Cross-Site Scripting (2.1.2)
WordPress Plugin WooSidebars Cross-Site Scripting (1.4.1)
WordPress Plugin Save Contact Form 7 SQL Injection (1.7)
WordPress Plugin AdServe 'id' Parameter SQL Injection (0.2)
WordPress Plugin WP smart CRM & Invoices FREE Cross-Site Scripting (1.8.7)