The mTheme-Unus theme for WordPress, prior to version 2.3, contained a directory traversal flaw that let attackers access arbitrary files. This was possible by exploiting the files parameter in css/css.php with .. sequences.
id: CVE-2015-9406
info:
name: mTheme Unus < 2.3 - Directory Traversal
author: pussycat0x
seve
...