Wordpress Alert: Arbitrary file read through download endpoints

A download handler accepts a path or ID outside the caller's allowed files. Private uploads or configuration files may be disclosed.

What it looks like

A download handler accepts a path or ID outside the caller's allowed files.

Why it matters

Private uploads or configuration files may be disclosed.

What to check

Verify path confinement and ownership checks for downloads.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP path traversal reference, WordPress roles and capabilities.