CVE-2014-4577
Absolute path traversal vulnerability in reviews.php in the WP AmASIN – The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full pathname in the url parameter.
Date published : 2014-10-21
http://plugins.svn.wordpress.org/wp-amasin-the-amazon-affiliate-shop/trunk/readme.txt
