cleantalk
Vulnerabilities and Security Researches

Download Manager, CVE-2021-24773

CVE, Research URL

CVE-2021-24773

Application

Download Manager

Published on
Nov 01, 2021
Research Description
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed
Affected versions
Min -, max 3.2.16.
Status
vulnerable