Description
WordPress Plugin MiwoFTP-File & Folder Manager is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin MiwoFTP-File & Folder Manager version 1.0.5 is vulnerable; other versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin WP Limit Login Attempts Security Bypass (2.6.4)
WordPress Plugin Anti Spam Protection without CAPTCHA powered by Keypic Security Bypass (2.1.2)
WordPress Plugin GDPR Cookie Compliance Security Bypass (4.0.2)
WordPress Plugin Tidio Gallery Multiple Vulnerabilities (1.1)
WordPress Plugin Invoicing with InvoiceXpress for WooCommerce-Free Cross-Site Scripting (3.0.2)