PT-2021-20606 · WordPress · Wordpress Download Manager
Ramuel Gall
·
Published
2021-08-05
·
Updated
2021-08-12
·
CVE-2021-34638
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
WordPress Download Manager versions 3.1.24 and prior versions
Description:
The issue allows authenticated users with Contributor+ roles to obtain sensitive configuration file information. Additionally, Author+ users can perform XSS attacks by setting the Download template to a file containing configuration information or an uploaded JavaScript with an image extension.
Recommendations:
For WordPress Download Manager versions 3.1.24 and prior, update to a version later than 3.1.24 to resolve the issue.
As a temporary workaround, consider restricting access to the Download template feature for Contributor+ and Author+ users until a patch is available.
Restrict the ability for users to upload files with executable content, such as JavaScript files with image extensions, to minimize the risk of XSS attacks.
Fix
XSS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wordpress Download Manager