Report
The WSM Downloader for WordPress is vulnerable to domain bypass due to insufficient hostname validation in the wsmd_user_download_request AJAX action in versions up to, and including, 1.4.0. This makes it possible for unauthenticated attackers to bypass domain name restrictions on download links to download files from non-acceptable files.
Score:5.3
Severity:Medium
Version: 1.4.0
The plugin vendor has not patched this vulnerability at the moment.