Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
| Software | From | Fixed in |
|---|---|---|
| lester_chan / wp-downloadmanager | - | 1.60.x |
| lester_chan / wp-downloadmanager | 1.00 | 1.00.x |
| lester_chan / wp-downloadmanager | 1.30 | 1.30.x |
| lester_chan / wp-downloadmanager | 1.31 | 1.31.x |
| lester_chan / wp-downloadmanager | 1.40 | 1.40.x |
| lester_chan / wp-downloadmanager | 1.50 | 1.50.x |