Description
WordPress Plugin Download Plugin is prone to a vulnerability that lets attackers download arbitrary directories because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Download Plugin version 1.0.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.2 or latest
References
Related Vulnerabilities
WordPress Plugin Duplicate Theme Unspecified Vulnerability (0.1.4)
phpList Access of Resource Using Incompatible Type ('Type Confusion') Vulnerability (CVE-2020-8547)
WordPress Plugin WP eCommerce 'cart_messages[]' Parameter Cross-Site Scripting (3.8.6)
WordPress Other Vulnerability (CVE-2007-3241)
MediaWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2023-45369)