Description
WordPress Plugin Download Theme is prone to a vulnerability that lets attackers download arbitrary directories because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Download Theme version 1.0.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.3 or latest
References
Related Vulnerabilities
Squid Out-of-bounds Write Vulnerability (CVE-2019-12519)
WordPress Plugin Fancy Product Designer-WooCommerce Arbitrary File Upload (4.6.8)
WordPress Plugin StreamCast-Radio Player for WordPress Cross-Site Scripting (2.1)
PHP Improper Handling of Exceptional Conditions Vulnerability (CVE-2014-1943)
MediaWiki Release of Invalid Pointer or Reference Vulnerability (CVE-2022-28203)