DM Albums for WordPress "delete_album" Directory Traversal Issue
Description
A vulnerability has been identified in DM Albums (plugin for WordPress), which could be exploited by attackers to bypass security restrictions. This issue is caused by missing access validation and an input validation error in the "dm-albums/wp-dm-albums-ajax.php" script wen processing the "delete_album" parameter, which could be exploited by attackers to delete arbitrary files and directories from a vulnerable web server.
Vulnerable Products
Vulnerable Software: DM Albums (plugin for WordPress) version 2.0 and prior