Download Manager < 3.2.22 - Subscriber+ Stored Cross-Site Scripting
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 0.6%
from disclosure to weapon
Published on NVDDec 27
VulnCheckNov 29
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
yesVulnCheck
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks
Affected products
Unknown · WordPress Download Manager