Absolute path traversal vulnerability in mysqldump_download.php in the WordPress Rename plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the dumpfname parameter.Referenceshttp://www.vapid.dhs.org/advisory.php?v=127http://www.openwall.com/lists/oss-security/2015/06/23/5http://www.securityfocus.com/bid/75394http://packetstormsecurity.com/files/132460/WordPress-WP-Instance-Rename-1.0-File-Download.htmlhttps://wpvulndb.com/vulnerabilities/8055