
CVE-2026-2426 The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'file' parameter in the file deletion fun… https://www.cve.org/CVERecord?id=CVE-2026-2426
Post summary
CVE-2026-2426 is a Path Traversal flaw in WP-DownloadManager (versions up to 1.69) affecting the 'file' parameter in the file deletion function.

