Input validation vulnerability in CM Download Manager 2.8.0

The CM Download Manager plugin for WordPress is not secure in versions up to 2.7.0. Hackers who have special privileges can insert malicious web scripts into pages which will be triggered each time a user visits the page. This is possible because the plugin does not adequately check the input and does not protect the output.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.