Description
WordPress Plugin DM Albums is prone to multiple vulnerabilities that can allow attackers to delete arbitrary files. The issues occur because the software fails to properly sanitize user-supplied input. Attackers can exploit these issues to delete arbitrary files on the victim's computer in the context of the vulnerable application. WordPress Plugin DM Albums versions prior to 2.1 are affected, but note that version 2.1 is still vulnerable to one of the issues.
Remediation
Update to plugin version 2.3.1 or latest
References
Related Vulnerabilities
WordPress Plugin Official MailerLite Sign Up Forms SQL Injection (1.4.3)
WordPress Plugin Motors-Car Dealer & Classified Ads Multiple Vulnerabilities (1.4.0)
WordPress Plugin WP Hide & Security Enhancer Arbitrary File Download (1.3.9.2)
Family Connections Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-4338)