Description
WordPress Plugin Download Plugin is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently activate plugins that are already installed. WordPress Plugin Download Plugin version 1.6.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6.1 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:4ED8296E-1306-481F-9A22-723B051122C0
https://plugins.svn.wordpress.org/download-plugin/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WP eCommerce 'cart_messages[]' Parameter Cross-Site Scripting (3.8.6)
WordPress Plugin NewStatPress Multiple Vulnerabilities (1.0.4)
Atlassian Jira Improper Authentication Vulnerability (CVE-2021-26070)
WordPress Plugin HTML5 Video Player-Best WordPress Video Player and Block SQL Injection (2.5.26)