First published: Thu Sep 04 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WPChill Download Monitor | =3.3.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4768 is considered a high severity vulnerability due to the potential for remote attackers to inject malicious scripts.
To fix CVE-2012-4768, update the Download Monitor plugin to version 3.3.5.9 or later.
CVE-2012-4768 affects users of the Download Monitor plugin versions prior to 3.3.5.9 installed on WordPress.
CVE-2012-4768 is a cross-site scripting (XSS) vulnerability allowing injection of arbitrary web scripts.
CVE-2012-4768 involves the dlsearch parameter which is manipulated to exploit the vulnerability.