CVE-2021-24773Cross-site Scripting in Download Manager

Severity
4.8MEDIUMNVD
EPSS
0.2%
top 57.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 1
Latest updateMay 24

Description

The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-6645-2q63-p5rq: The WordPress Download Manager WordPress plugin before 32022-05-24
CVEList
WordPress Download Manager < 3.2.16 - Admin+ Stored Cross-Site Scripting2021-11-01
CVE-2021-24773 — Cross-site Scripting | cvebase