Description
WordPress Plugin Simple Download Button Shortcode is prone to an information disclosure vulnerability because it fails to properly sanitize user-supplied input. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Simple Download Button Shortcode version 1.0 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 1.1 or latest
References
Related Vulnerabilities
WordPress 5.5.x PHP Object Injection (5.5 - 5.5.4)
Oracle JRE CVE-2012-3213 Vulnerability (CVE-2012-3213)
IBM WebSEAL Inadequate Encryption Strength Vulnerability (CVE-2019-4151)
WordPress Plugin Catpro Gallery Arbitrary File Upload (3.8)
WordPress Plugin Mitsol Social Post Feed Cross-Site Scripting (1.10)