cleantalk
Vulnerabilities and Security Researches

Download Manager, CVE-2019-15889

CVE, Research URL

CVE-2019-15889

Application

Download Manager

Published on
Sep 03, 2019
Research Description
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
Affected versions
Min -, max 2.9.94.
Status
vulnerable