Description
WordPress Plugin Theme My Login is prone to a local file inclusion vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Theme My Login version 6.3.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.3.10 or latest
References
https://security.dxw.com/advisories/lfi-in-theme-my-login/
http://packetstormsecurity.com/files/127302/WordPress-Theme-My-Login-6.3.9-Local-File-Inclusion.html
http://seclists.org/fulldisclosure/2014/Jun/172
Related Vulnerabilities
WordPress Plugin Welcart e-Commerce Multiple Vulnerabilities (1.8.2)
WordPress Plugin Contact Form 7 Arbitrary File Upload (3.5.3)
WordPress Plugin BuddyPress Information Disclosure (5.1.1)
WordPress Plugin Thrive Themes Builder Security Bypass (2.2.3)
WordPress Plugin Payment Form for PayPal Pro Multiple Cross-Site Scripting Vulnerabilities (1.0.1)