vendor:
WordPress Download Manager
by:
ThuraMoeMyint
7.5
CVSS
HIGH
Cross-site Scripting
79
CWE
Product Name: WordPress Download Manager
Affected Version From: 2.9.93
Affected Version To: 2.9.93
Patch Exists: Yes
Related CWE: CVE-2019-15889
CPE: a:wpdownloadmanager:wordpress_download_manager
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WebApps, WordPress
2019
WordPress Download Manager Cross-site Scripting
In the pro features of the WordPress download manager plugin, there is a Category Short-code feature witch can use to sort categories with order by a function which will be used as ?orderby=title,publish_date. By adding parameter '>' and add any XSS payload, the xss payload will execute.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of the plugin.