Description
WordPress Plugin Download Plugin is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently activate plugins that are already installed. WordPress Plugin Download Plugin version 1.6.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6.1 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:4ED8296E-1306-481F-9A22-723B051122C0
https://plugins.svn.wordpress.org/download-plugin/trunk/readme.txt
Related Vulnerabilities
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0372)
Jboss EAP Improper Input Validation Vulnerability (CVE-2020-1757)
WordPress Plugin Rencontre-Dating Site Multiple Vulnerabilities (3.1.2)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-6379)