Wordpress DM Albums Plugin security_file Remote File Inclusion Exploit

Input passed to the SECURITY_FILE parameter in wp-content/plugins/dm-albums/template/album.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources.
Product Name