Record summary

CVE-2018-16363 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress File Manager < 3.0 - Cross-Site Scripting

WordPress File Manager plugin before 3.0 is vulnerable to authenticated reflected cross-site scripting (XSS) via the lang parameter in the admin dashboard. The parameter is directly echoed into a JavaScript context without proper sanitization.

AuthorsShivam Kamboj
Template tagscvecve2018xsswp-file-managerwordpresswpauthenticated

Source: ProjectDiscovery

References

5