CVE-2013-7319
WordPress Download Mgr <2.5.9 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Jeroen - IT Nerdbox · textwebappsphp
https://www.exploit-db.com/exploits/30105
Scores
EPSS
0.0454
EPSS Percentile
89.1%
Details
CWE
CWE-79
Status
published
Products (10)
w3eden/download_manager
< 2.5.8
w3eden/download_manager
w3eden/download_manager
w3eden/download_manager
w3eden/download_manager
w3eden/download_manager
w3eden/download_manager
w3eden/download_manager
w3eden/download_manager
n/a/n/a
Published
Feb 06, 2014
Tracked Since
Feb 18, 2026