WordPress plugin W3 Total Cache before version 0.9.4 allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data via pub/sns.php.
View the template here CVE-2019-6715.yaml
References:
https://github.com/random-robbie/cve-2019-6715