Download Manager, 413f54781ffb5ef3531adbeaaf6527a75a4cd160
- CVE, Research URL
- Home page URL
- Application
- Published on
- Apr 30, 2021
- Research Description
- Download Manager [download-manager] < 3.1.19 WordPress Download Manager < 3.1.19 - Arbitrary File Upload The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpdm_admin_upload_file function in versions before 3.1.19. Dangerous extensions such as .php4 are not restricted. This makes it possible for authenticated attackers with Author-level privileges and above to upload arbitrary files on the affected sites server which may make remote code execution possible.
- Affected versions
-
max 3.1.19.
- Status
-
vulnerable