Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure of the installation path in a stack trace.
Attackers can exploit this issue using a browser or readily available tools. The following example data is available:
http://downloads.securityfocus.com/vulnerabilities/exploits/56739.txt