The Market Exporter plugin for WordPress has a security issue that could cause data to be lost without proper authorization. This is because the ‘remove_files’ function in all versions, up to and including 2.0.19, does not have a capability check. This means that attackers with Subscriber-level access or higher can delete any files they want on the server by using path traversal.