A directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.
View the template here CVE-2013-7240.yaml
References:
http://seclists.org/oss-sec/2013/q4/566