EKC Tournament Manager WordPress plugin < 2.2.2 contains a path traversal caused by insufficient validation, letting logged in admin users download system files outside the WordPress directory.
id: CVE-2024-9765
info:
name: EKC Tournament Manager WordPress plugin - Path Traversal
author:
...