CVE-2019-15889
MEDIUMNuclei
WordPress Plugin Download Manager 2.9.93 - Cross-Site Scripting
Record summary
CVE-2019-15889 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Download Manager 2.9.93 - Cross-Site ScriptingExploitDB exploitby MgThuraMoeMyintNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Download Manager <2.9.94 - Cross-Site ScriptingCVSS 6.1
WordPress Download Manager plugin before 2.9.94 contains a cross-site scripting vulnerability via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
Impact
Successful exploitation of this vulnerability could lead to the execution of arbitrary script code in the context of the affected website, potentially allowing an attacker to steal sensitive information or perform unauthorized actions.
Remediation
Update WordPress Download Manager plugin to version 2.9.94 or later to mitigate this vulnerability.
WeaknessesCWE-79
Authorsdaffainfo
Template tagscvecve2019packetstormwordpressxsswp-pluginwpdownloadmanagervuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wpdownloadmanager:wordpress_download_manager:*:*:*:*:*:wordpress:*:*
https://www.cybersecurity-help.cz/vdb/SB2019041819 https://wordpress.org/plugins/download-manager/#developers https://nvd.nist.gov/vuln/detail/CVE-2019-15889 http://packetstormsecurity.com/files/154356/WordPress-Download-Manager-2.9.93-Cross-Site-Scripting.html https://plugins.trac.wordpress.org/changeset/2070388/download-manager
Source: ProjectDiscovery
References
8packetstormsecurity.com
http://packetstormsecurity.com/files/154356/WordPress-Download-Manager-2.9.93-Cross-Site-Scripting.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-15889 packetstormsecurity.com
https://packetstormsecurity.com/files/152511/WordPress-Download-Manager-2.9.92-Cross-Site-Scripting.html packetstormsecurity.com
https://packetstormsecurity.com/files/152552/WordPress-Download-Manager-2.9.93-Cross-Site-Scripting.html plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/2070388/download-manager wordpress.org
https://wordpress.org/plugins/download-manager wpvulndb.com
https://wpvulndb.com/vulnerabilities/9257 cybersecurity-help.cz
https://www.cybersecurity-help.cz/vdb/SB2019041819