Description
WordPress Plugin DM Albums is prone to multiple vulnerabilities that can allow attackers to delete arbitrary files. The issues occur because the software fails to properly sanitize user-supplied input. Attackers can exploit these issues to delete arbitrary files on the victim's computer in the context of the vulnerable application. WordPress Plugin DM Albums versions prior to 2.1 are affected, but note that version 2.1 is still vulnerable to one of the issues.
Remediation
Update to plugin version 2.3.1 or latest
References
Related Vulnerabilities
e107 Other Vulnerability (CVE-2010-0996)
Apache Tomcat Resource Management Errors Vulnerability (CVE-2011-4858)
WordPress Plugin GiveWP-Donation and Fundraising Platform Cross-Site Request Forgery (2.25.2)
WebLogic Improper Input Validation Vulnerability (CVE-2017-15707)
WordPress Plugin Enable Media Replace Directory Traversal (3.6.3)