WordPress Plugin Vulnerabilities

CM Download Manager < 2.8.0 - Unauthenticated Reflected Cross Site Scripting (XSS)

Description

The plugin is vulnerable to Unauthenticated Cross Site Scripting (XSS) before version 2.8.0.

Affects Plugins

Fixed in 2.8.0

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Suzhou Aurora Infinity Information Technology Co., Ltd
Verified
Yes

Timeline

Publicly Published
2021-04-13 (about 5 years ago)
Added
2021-07-09 (about 4 years ago)
Last Updated
2021-08-10 (about 4 years ago)

Other