Record summary

CVE-2019-15889 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Download Manager 2.9.93 - Cross-Site ScriptingExploitDB exploitby MgThuraMoeMyintNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Download Manager <2.9.94 - Cross-Site ScriptingCVSS 6.1

WordPress Download Manager plugin before 2.9.94 contains a cross-site scripting vulnerability via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.

Impact

Successful exploitation of this vulnerability could lead to the execution of arbitrary script code in the context of the affected website, potentially allowing an attacker to steal sensitive information or perform unauthorized actions.

Remediation

Update WordPress Download Manager plugin to version 2.9.94 or later to mitigate this vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscvecve2019packetstormwordpressxsswp-pluginwpdownloadmanagervuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wpdownloadmanager:wordpress_download_manager:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

8