SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the show parameter in the QUERY_STRING to the default URI.
https://www.exploit-db.com/exploits/37080/
https://euvd.enisa.europa.eu/vulnerability/EUVD-2015-3371
http://www.securityfocus.com/bid/74237
http://packetstormsecurity.com/files/131801/WordPress-WP-Symposium-15.1-SQL-Injection.html