The plugin does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress powered site. This includes details of even privately published posts and password protected posts with their passwords revealed in plain text.
View the template here CVE-2015-20067.yaml
References:
https://github.com/ARPSyndicate/cvemon