Likely 0-day
Detected Download Monitor plugin before 1.9.7 exposed the full download log CSV to unauthenticated users, revealing fields including User Login, User Email, User IP, and User Agent for every recorded download.
id: download-monitor-unauth-log-export
info:
name: Download Monitor < 1.9.7 - Unauthenticated Dow
...