Description
WordPress Plugin Slider Revolution Responsive is prone to a local file inclusion vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Slider Revolution Responsive version 4.1.4 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 4.2 or latest
References
https://blog.sucuri.net/2014/09/slider-revolution-plugin-critical-vulnerability-being-exploited.html
http://www.homelab.it/index.php/2014/07/28/wordpress-slider-revolution-arbitrary-file-download/
Related Vulnerabilities
WordPress Plugin WP-Spreadshirt-Gallery Cross-Site Scripting (1.3)
WordPress Plugin Mailster-Email Newsletter for WordPress Cross-Site Scripting (2.4.5.1)
WordPress Plugin Human Presence Cross-Site Scripting (2.0.8)
WordPress Plugin Sharebar Cross-Site Scripting and SQL Injection Vulnerabilities (1.2.1)
WordPress 'edit.php' Cross-Site Scripting Vulnerability (1.5)