PT-2021-20606 · WordPress · Wordpress Download Manager

Ramuel Gall

·

Published

2021-08-05

·

Updated

2021-08-12

·

CVE-2021-34638

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: WordPress Download Manager versions 3.1.24 and prior versions
Description: The issue allows authenticated users with Contributor+ roles to obtain sensitive configuration file information. Additionally, Author+ users can perform XSS attacks by setting the Download template to a file containing configuration information or an uploaded JavaScript with an image extension.
Recommendations: For WordPress Download Manager versions 3.1.24 and prior, update to a version later than 3.1.24 to resolve the issue. As a temporary workaround, consider restricting access to the Download template feature for Contributor+ and Author+ users until a patch is available. Restrict the ability for users to upload files with executable content, such as JavaScript files with image extensions, to minimize the risk of XSS attacks.

Fix

XSS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34638

Affected Products

Wordpress Download Manager