Access violation vulnerability in Download Manager 2.8.8

The Download Manager plugin for WordPress is a tool that website administrators use to manage downloads. Unfortunately, versions of this plugin up to and including 2.8.7 have a security issue that could allow an attacker to gain access to things they shouldn’t. This security issue is caused by the extract() function not being properly checked. This means that if an attacker had access to the website with the plugin installed, they could potentially edit user data, such as their role, even if the attacker only had a “subscriber” level of access.

Detected in:

Download Manager fixed vulnerable versions: >= * < 2.8.8
Download Manager Pro fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.