Extension WordPress
Vulnérabilités CM Download Manager – Organize, Protect & Share Files in WordPress
Cette page rassemble les failles publiées pour CM Download Manager – Organize, Protect & Share Files in WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de CM Download Manager – Organize, Protect & Share Files in WordPress
10 fiches
CM Download Manager <= 2.9.6 – Unauthenticated Arbitrary File Deletion
The CM Download Manager – Simplify file sharing with powerful download management plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deletescreenshot() function in all versions up to, and including,…
*-2.9.6
3.0.0
27/03/2025
CM Download Manager < 2.9.0 – Cross-Site Request Forgery via unpublishHeader
The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.9.0. This is due to missing or incorrect nonce validation on the 'unpublishHeader' function. This makes it possible for unauthenticated attackers…
[*, 2.9.0)
2.9.0
25/03/2024
CM Download Manager < 2.9.1 – Cross-Site Request Forgery via editHeader
The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.9.1. This is due to missing or incorrect nonce validation on the 'editHeader' function. This makes it possible for unauthenticated attackers…
[*, 2.9.1)
2.9.1
25/03/2024
CM Download Manager < 2.9.0 – Cross-Site Request Forgery via delHeader
The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2.9.0. This is due to missing or incorrect nonce validation on the 'delHeader' function. This makes it possible for unauthenticated attackers…
[*, 2.9.0)
2.9.0
25/03/2024
CM Download Manager <= 2.8.5 – Authenticated (Administrator+) Arbitrary File Upload
The CM Download Manager plugin for WordPress is vulnerable to arbitrary file uploads because it allows administrators to choose the php extension as an allowable file extension in versions up to, and including, 2.8.5. This makes it possible…
*-2.8.5
2.8.6
05/09/2022
CM Download Manager < 2.8.0 – Directory Traversal to Arbitrary File Deletion and Denial of Service
Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.
[*, 2.8.0)
2.8.0
13/04/2021
CM Download Manager <= 2.7.0 – Cross-Site Scripting
The CM Download Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.7.0 via a crafted deletescreenshot action due to insufficient input sanitization and output escaping. This makes it possible for attackers…
[*, 2.8.0)
2.8.0
13/04/2021
CM Download Manager <= 2.7.0 – Authenticated Stored Cross-Site Scripting
The CM Download Manager plugin for WordPress is vulnerable to Authenticated Stored Cross-Site Scripting via the ‘filename’ parameter in versions up to, and including, 2.7.0 due to insufficient input sanitization and output escaping. This makes it possible for…
[*, 2.8.0)
2.8.0
22/10/2020
CM Download Manager <= 2.0.6 – Cross-Site Request Forgery to Cross-Site Scripting
Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in…
*-2.0.6
2.0.7
01/12/2014
CM Download Manager <= 2.0.3 – Code Injection
The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function.
*-2.0.3
2.0.4
10/11/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.