CVE-2021-34638
The WordPress Download Manager plugin before version 3.1.25 contains an authenticated directory traversal vulnerability that permits users with Contributor role or higher to read sensitive configuration files by manipulating the Download template setting. Additionally, users with Author privileges and above can execute cross-site scripting attacks by uploading JavaScript files with image extensions and specifying them as the Download template. This flaw impacts all installations running version 3.1.24 and earlier.
Based on public CVE data (MITRE/NVD).