The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php`
https://wpscan.com/vulnerability/d40c7108-bad6-4ed3-8539-35c0f57e62cc