Description
WordPress Plugin Download Manager is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to delete arbitrary files in the context of the webserver process. WordPress Plugin Download Manager version 3.2.50 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.51 or latest
References
Related Vulnerabilities
WebLogic CVE-2019-2647 Vulnerability (CVE-2019-2647)
Oracle Database Server Other Vulnerability (CVE-2001-0941)
WordPress Plugin Pinterest Automatic Pin Security Bypass (4.14.3)
WordPress Plugin Grow by Tradedoubler-Advertiser for WooCommerce Local File Inclusion (2.0.21)
Oracle Database Server CVE-2011-2240 Vulnerability (CVE-2011-2240)