WP-DownloadManager, CVE-2022-25605
- CVE, Research URL
- Home page URL
- Application
- Published on
- Mar 18, 2022
- Research Description
- Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url.
- Affected versions
-
max 1.68.7.
- Status
-
vulnerable