Description
WordPress Plugin Theme My Login is prone to a local file inclusion vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Theme My Login version 6.3.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.3.10 or latest
References
https://security.dxw.com/advisories/lfi-in-theme-my-login/
http://packetstormsecurity.com/files/127302/WordPress-Theme-My-Login-6.3.9-Local-File-Inclusion.html
http://seclists.org/fulldisclosure/2014/Jun/172
Related Vulnerabilities
Ruby on Rails Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0276)
WordPress Plugin Gallery-Responsive Photo and Video Gallery by Limb Cross-Site Scripting (1.3.2)
WordPress Plugin Drug Search Cross-Site Scripting (1.0.0)
WordPress Plugin Telefication Server-Side Request Forgery (1.8.0)