PT-2022-7970 · WordPress · Wp-Filebase Download Manager Plugin

Yorick Koster

·

Published

2022-06-24

·

Updated

2022-06-30

·

CVE-2017-20097

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP-Filebase Download Manager Plugin version 3.4.4
Description A vulnerability was found in the WP-Filebase Download Manager Plugin, which can be exploited to perform basic cross-site scripting. The attack may be launched remotely, affecting some unknown functionality of the plugin.
Recommendations For WP-Filebase Download Manager Plugin version 3.4.4, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the plugin's functionality to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20097

Affected Products

Wp-Filebase Download Manager Plugin