cleantalk
Vulnerabilities and Security Researches

Download Manager, 9f865ea2da941668d15a46e0d2f58ce77f2047df

Application

Download Manager

Published on
Apr 30, 2021
Research Description
Download Manager [download-manager] < 3.1.22 WordPress Download Manager < 3.1.22 - Cross-Site Request Forgery The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 3.1.22. This is due to missing or incorrect nonce validation on the pluginUpdate() and Privacy() functions. This makes it possible for unauthenticated attackers to arbitrarily modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 3.1.22.
Status
vulnerable