First published: Fri Apr 19 2013(Updated: )
Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Download Manager Pro | <=1.60 | |
WordPress Download Manager Pro | =1.00 | |
WordPress Download Manager Pro | =1.30 | |
WordPress Download Manager Pro | =1.31 | |
WordPress Download Manager Pro | =1.40 | |
WordPress Download Manager Pro | =1.50 | |
WordPress |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2697 is rated as a moderate severity vulnerability that can lead to cross-site request forgery (CSRF) attacks.
To fix CVE-2013-2697, update the WP-DownloadManager plugin to version 1.61 or higher.
CVE-2013-2697 affects versions of WP-DownloadManager prior to 1.61.
Yes, CVE-2013-2697 can allow remote attackers to hijack the authentication of arbitrary users and perform unauthorized actions.
CVE-2013-2697 can lead to cross-site scripting (XSS) sequences being inserted through CSRF exploits.