CVE-2012-10025 | Advanced Custom Fields Plugin up to 3.5.1 on WordPress POST Parameter core/actions/export.php acf_abspath filename control (EDB-23856 / Nessus ID 63326)
A vulnerability was found in Advanced Custom Fields Plugin up to 3.5.1 on WordPress and classified as critical. This issue affects some unknown processing of the file core/actions/export.php of the component POST Parameter Handler. The manipulation of the argument acf_abspath leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
The identification of this vulnerability is CVE-2012-10025. The attack may be initiated remotely. Furthermore, there is an exploit available.