Input validation vulnerability in CM Download Manager – Document and File Management 2.9.1

The CM Download Manager plugin for WordPress has a security issue in versions up to 2.9.1. This is because the ‘editHeader’ function does not properly validate nonces, which can allow attackers to edit downloads without being authenticated. This can happen if a site administrator is tricked into clicking on a link.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.