Description
WordPress Plugin DM Albums is prone to multiple vulnerabilities that can allow attackers to delete arbitrary files. The issues occur because the software fails to properly sanitize user-supplied input. Attackers can exploit these issues to delete arbitrary files on the victim's computer in the context of the vulnerable application. WordPress Plugin DM Albums versions prior to 2.1 are affected, but note that version 2.1 is still vulnerable to one of the issues.
Remediation
Update to plugin version 2.3.1 or latest
References
Related Vulnerabilities
qdPM Multiple Cross-site Scripting (XSS) Vulnerabilities (CVE-2015-3883)
PHP Other Vulnerability (CVE-2007-1700)
Ruby Improper Authentication Vulnerability (CVE-2007-5162)
Liferay Portal Improper Authentication Vulnerability (CVE-2021-29047)
WordPress Plugin WP Statistics Cross-Site Scripting (12.0.9)