WordPress Localize My Post 1.0 is susceptible to local file inclusion via the ajax/include.php file parameter.
View the template here CVE-2018-16299.yaml
References:
https://packetstormsecurity.com/files/149433/WordPress-Localize-My-Post-1.0-Local-File-Inclusion.html