Input validation vulnerability in Downloads Manager 0.2

The Downloads Manager plugin for WordPress is not secure in versions up to 0.2. Attackers can upload any type of file to the affected website server through the ‘upfile’ parameter. This could allow them to run malicious code remotely when the file is accessed from the wp-content/plugins/downloads-manager/upload/ directory.

Detected in:

Downloads Manager open vulnerable versions: >= * <= 0.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.