WordPress Simple Image Manipulator 1.0 is vulnerable to local file inclusion in ./simple-image-manipulator/controller/download.php because no checks are made to authenticate users or sanitize input when determining file location.
View the template here CVE-2015-1000010.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2015-1000010