Description
WordPress Plugin Download Theme is prone to a vulnerability that lets attackers download arbitrary directories because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Download Theme version 1.0.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.3 or latest
References
Related Vulnerabilities
Jboss EAP Uncontrolled Resource Consumption Vulnerability (CVE-2019-14888)
e107 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-50907)
Squid Improper Input Validation Vulnerability (CVE-2012-5643)
MySQL CVE-2014-4287 Vulnerability (CVE-2014-4287)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5473)