CVE-2015-1579
The Slider Revolution plugin (revslider) before version 4.1.5 contains a directory traversal flaw that enables attackers to access arbitrary files on the server. By inserting dot-dot sequences into the img parameter when making requests to the revslider_show_image action via wp-admin/admin-ajax.php, an unauthenticated remote attacker can read sensitive files outside the intended directory. This vulnerability remains unfixed in the affected versions and may overlap with a previously reported issue tracked as CVE-2014-9734.
Based on public CVE data (MITRE/NVD).