CVE-2012-1205
PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
Date published : 2012-02-20
http://www.securityfocus.com/bid/49693
http://plugins.trac.wordpress.org/changeset/504380/relocate-upload