CVE-2014-5155
The Theme My Login plugin before version 6.3.10 contains a local file inclusion vulnerability in the login_template attribute of its shortcode that allows authenticated attackers to include and execute arbitrary files on the server. An attacker with login credentials can exploit this flaw to run any PHP code contained in accessible files, potentially bypassing security restrictions, stealing sensitive information, or executing malicious code through uploaded files that appear innocuous.
Based on public CVE data (MITRE/NVD).