Input validation vulnerability in Download Manager 2.9.6

The WordPress Download Manager plugin is vulnerable to a type of attack called Cross-Site Request Forgery in versions up to 2.9.6. This means that unauthenticated attackers can send malicious links to a site administrator and if the administrator clicks on them, they can install malicious plugins or packages. This is because the plugin is missing or not correctly validating nonce validation on the wpdm_install_addon function. To protect yourself against this attack, you should update the WordPress Download Manager plugin to the latest version.

Detected in:

Download Manager fixed vulnerable versions: >= * <= 2.9.6
Download Manager Pro fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.