CM Download Manager – Document and File Management, CVE-2024-1231
- CVE, Research URL
- Published on
- Mar 25, 2024
- Research Description
- The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack
- Affected versions
-
Min -, max 2.9.0.
- Status
-
vulnerable