Description
The WordPress plugin Slider Revolution was vulnerable to an arbitrary file disclosure vulnerability that allows an attacker to download any file from the server. This vulnerability is/was actively exploited in the wild.
Remediation
Upgrade to the latest version of the plugin.
References
Related Vulnerabilities
WordPress Plugin Localize My Post Local File Inclusion (1.0)
Joomla! Core 3.7.x Information Disclosure (3.7.0 - 3.7.5)
WordPress Plugin Visual Composer:Page Builder for WordPress Local File Inclusion (5.1)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-7951)