EKC Tournament Manager WordPress plugin < 2.2.2 contains a path traversal caused by insufficient validation, letting logged in admin users download system files outside the WordPress directory.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view