PT-2022-7970 · WordPress · Wp-Filebase Download Manager Plugin
Yorick Koster
·
Published
2022-06-24
·
Updated
2022-06-30
·
CVE-2017-20097
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP-Filebase Download Manager Plugin version 3.4.4
Description
A vulnerability was found in the WP-Filebase Download Manager Plugin, which can be exploited to perform basic cross-site scripting. The attack may be launched remotely, affecting some unknown functionality of the plugin.
Recommendations
For WP-Filebase Download Manager Plugin version 3.4.4, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the plugin's functionality to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp-Filebase Download Manager Plugin