cleantalk
Vulnerabilities and Security Researches

Download Manager, 413f54781ffb5ef3531adbeaaf6527a75a4cd160

Application

Download Manager

Published on
Apr 30, 2021
Research Description
Download Manager [download-manager] < 3.1.19 WordPress Download Manager < 3.1.19 - Arbitrary File Upload The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpdm_admin_upload_file function in versions before 3.1.19. Dangerous extensions such as .php4 are not restricted. This makes it possible for authenticated attackers with Author-level privileges and above to upload arbitrary files on the affected sites server which may make remote code execution possible.
Affected versions
max 3.1.19.
Status
vulnerable