PT-2024-37452 · WordPress · Download Manager
Jack Taylor
·
Published
2024-07-31
·
Updated
2025-03-21
·
CVE-2024-6208
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Download Manager plugin for WordPress versions up to, and including, 3.2.97
Description:
The issue is related to Stored Cross-Site Scripting in the Download Manager plugin for WordPress. This occurs via the plugin's 'wpdm all packages' shortcode due to insufficient input sanitization and output escaping on the
cols parameter. Authenticated attackers with contributor-level access and above can inject arbitrary web scripts in pages, which will execute when a user accesses an injected page.Recommendations:
For versions up to, and including, 3.2.97, update to a version higher than 3.2.97 to resolve the issue.
As a temporary workaround, consider restricting access to the 'wpdm all packages' shortcode until a patch is available.
Avoid using the
cols parameter in the 'wpdm all packages' shortcode until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Download Manager