The ghost plugin prior to 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.
ghost ghost