Input validation vulnerability in Download Plugin 2.0.5

The Download Plugin plugin for WordPress is vulnerable to a type of security attack called Cross-Site Request Forgery. This means that in versions of the plugin up to and including 2.0.4, attackers can make a request that tricks the site administrator into downloading plugin zips without the administrator’s knowledge or permission. This happens because the plugin does not include security checks called nonce validation on certain functions.

Detected in:

Download Plugin fixed vulnerable versions: >= * < 2.0.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.