PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPress before 1.8 allows remote attackers to execute arbitrary PHP code via a URL in the dompdf parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/81931
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0735
http://www.securityfocus.com/bid/57768
http://wordpress.org/plugins/wp-ecommerce-shop-styling/changelog/