The plugin does not properly validate the path of the file saved within the download post to ensure it is a safe file type or is associated with a download post. As a result, authenticated users able to create downloads, could delete arbitrary files from the server
2022-08-03 (about 6 months ago)
2022-08-03 (about 6 months ago)
2022-08-03 (about 6 months ago)