Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the wpPATH parameter. Successful exploitation requires that register_globals is enabled.
Publication date: Thu, 03 May 2007 22:19:00 +0000