JVN#79738260Third-party advisory
https://jvn.jp/en/jp/JVN79738260/index.html CVE-2017-2217
MEDIUM
Record summary
CVE-2017-2217 has a selected CVSS score of 6.1 (medium).
Description
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WordPress Download ManagerBrowse W3 Eden, Inc. / WordPress Download Manager | CVE List | prior to version 2.9.51 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-2217 plugins.trac.wordpress.orgConfirmation
https://plugins.trac.wordpress.org/changeset/1650075 wordpress.orgConfirmation
https://wordpress.org/plugins/download-manager