Description
WordPress Plugin Download Theme is prone to a vulnerability that lets attackers download arbitrary directories because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Download Theme version 1.0.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.3 or latest
References
Related Vulnerabilities
WordPress Plugin WP Google Maps Multiple Cross-Site Scripting Vulnerabilities (8.1.12)
Oracle JRE CVE-2013-0430 Vulnerability (CVE-2013-0430)
WordPress Plugin Profile Extra Fields by BestWebSoft Cross-Site Scripting (1.0.7)
IBM RTC Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-4946)