Description
WordPress Plugin Download Theme is prone to a vulnerability that lets attackers download arbitrary directories because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Download Theme version 1.0.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.3 or latest
References
Related Vulnerabilities
Magento Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2019-7872)
Oracle JRE CVE-2013-0442 Vulnerability (CVE-2013-0442)
MySQL CVE-2019-2785 Vulnerability (CVE-2019-2785)
ownCloud Improper Input Validation Vulnerability (CVE-2013-1939)
phpList Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-22249)