CVE-2021-31567
Download Monitor versions 4.4.6 and earlier contain an authenticated arbitrary file download vulnerability that affects users with admin privileges. An authenticated administrator can exploit the downloadable_file_urls[0] parameter to download sensitive files from the server, such as wp-config.php, or access files outside the web root directory by traversing the file system. This flaw allows unrestricted access to arbitrary files on the operating system where the WordPress installation resides. The vulnerability has been addressed in version 4.4.7.
Based on public CVE data (MITRE/NVD).