cleantalk
Vulnerabilities and Security Researches

CM Download Manager – Document and File Management, CVE-2024-1231

CVE, Research URL

CVE-2024-1231

Published on
Mar 25, 2024
Research Description
The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack
Affected versions
Min -, max 2.9.0.
Status
vulnerable