nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24969 CVE-2021-24969
MEDIUM
Download Manager < 3.2.22 - Subscriber+ Stored Cross-Site Scripting
Record summary
CVE-2021-24969 has a selected CVSS score of 5.4 (medium).
Description
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 29, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WordPress Download Manager | CVE List | 3.2.22 to < 3.2.22 | affected |
download_managerBrowse w3eden / download_manager | VulnCheck | Version data not supplied | |
References
2wpscan.com
https://wpscan.com/vulnerability/01144c50-54ca-44d9-9ce8-bf4f659114ee