Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local network hosts and execute command on services
| Software | From | Fixed in |
|---|---|---|
| wp-downloadmanager_project / wp-downloadmanager | 1.68.4 | 1.68.4.x |