Description
WordPress Plugin CM Download Manager is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary code within the context of the affected webserver process; this may result in total compromise of the web server. WordPress Plugin CM Download Manager version 2.0.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.4 or latest
References
http://seclists.org/bugtraq/2014/Nov/103
http://www.exploit-db.com/exploits/35324/
http://packetstormsecurity.com/files/129183/WordPress-CM-Download-Manager-2.0.0-Code-Injection.html
Related Vulnerabilities
WordPress Plugin 5gig Concerts Unspecified Vulnerability (1.0)
Django Resource Management Errors Vulnerability (CVE-2014-0474)
Apache Tomcat Other Vulnerability (CVE-2008-0002)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20100)
Ruby on Rails Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-0447)