kg_callffmpeg.php in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to execute arbitrary commands via unspecified vectors.
https://exchange.xforce.ibmcloud.com/vulnerabilities/73508
http://www.securityfocus.com/bid/52180
http://wordpress.org/extend/plugins/video-embed-thumbnail-generator/changelog/