CVE-2020-24146

HIGH

WordPress cm-download-manager <2.7.0 - Path Traversal

Title source: llm
STIX 2.1

Description

Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://wordpress.org/plugins/cm-download-manager/#developers

Scores

CVSS v3 8.1
EPSS 0.0167
EPSS Percentile 73.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
cminds/cm_download_manager 2.7.0
Published Jul 07, 2021
Tracked Since Feb 18, 2026