WordPress Simple Image Manipulator 1.0 is vulnerable to local file inclusion in ./simple-image-manipulator/controller/download.php because no checks are made to authenticate users or sanitize input when determining file location.
id: CVE-2015-1000010
info:
name: WordPress Simple Image Manipulator < 1.0 - Local File Inclusion
...