Description
WordPress Plugin Download Manager is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to delete arbitrary files in the context of the webserver process. WordPress Plugin Download Manager version 3.2.50 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.51 or latest
References
Related Vulnerabilities
WordPress Plugin Under Construction Unspecified Vulnerability (3.25)
WordPress Plugin Popup-Popup More Popups Directory Traversal (2.2.4)
WordPress Plugin Page Visit Counter SQL Injection (4.0.9)
WordPress Plugin Smart Slider 3 Cross-Site Scripting (3.5.0.8)
WordPress Plugin WP Visitor Statistics (Real Time Traffic) Unspecified Vulnerability (4.8)