Details ================ Software: Subscribe to Comments Version: 2.1.2 Homepage: http://wordpress.org/plugins/subscribe-to-comments/ Advisory report: https://security.dxw.com/advisories/admin-only-local-file-inclusion-and-arbitrary-code-execution-in-subscribe-to-comments-2-1-2/ CVE: Awaiting assignment CVSS: 8 (High; AV:N/AC:L/Au:S/C:C/I:P/A:P) Description ================ Admin-only local file inclusion and arbitrary code execution in Subscribe to Comments 2.1.2 Vulnerability ================ Administrators can perform Local File include attacks, which is a privilege escalation on systems where the administrator doesn’t have control over the server. If administrators can upload PHP files (or any file which can contain “