ZeroHour

CVE-2021-24773

PoC
CVSS 3.1
4.8 medium
EPSS
3%p86
Published
()
Modified
Description

The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed

Vendors
w3eden
Products
download manager
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.