vendor:
Sell Downloads
by:
Mr Winst0n
7.5
CVSS
HIGH
Cross Site Scripting
79
CWE
Product Name: Sell Downloads
Affected Version From: 1.0.86
Affected Version To: 1.0.86
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:sell_downloads
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Parrot OS, Wordpress 5.1.1
2019
WordPress Plugin Sell Downloads 1.0.86 – Cross Site Scripting
A Cross-Site Scripting (XSS) vulnerability was discovered in the WordPress Plugin Sell Downloads 1.0.86. An attacker can inject malicious JavaScript code into the comment field of a product, which will be executed when the product page is viewed. This can be used to steal session cookies or perform other malicious actions.
Mitigation:
The vendor has released version 1.0.87 which fixes this vulnerability.