Description
SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.
Affected products
- arnos_toolbox / wp-download1.2 – 1.2
- WordPress / wp_download1.2 – 1.2