Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24143
Reference (s):
- https://github.com/secwx/research/blob/main/cve/CVE-2020-24143.md

