Can you tell me if this note is true?
What is the fix for this?
“About 2 months ago , someone publicly disclosed a serious vulnerability in the WordPress Plugin Slider Revolution Premium which allows a remote attacker to download any file from the server .
The shared concept of evidence through illegal sites shows how someone can easily download the wp -config.php :
http://victim.com/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
This is used to steal the credentials of the database , which then allows you to compromise the site through the database.
This type of vulnerability is known as a Local File Inclusion attack ( LFI ) . The attacker is able to access, review , download a local file on the server. This, in case you’re asking is a very serious vulnerability that should be addressed immediately.”