First published: Fri Jul 07 2017(Updated: )
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Download Manager | <=2.9.49 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2216 has been classified as a medium severity cross-site scripting vulnerability that affects multiple versions of WordPress Download Manager.
To fix CVE-2017-2216, you should update WordPress Download Manager to version 2.9.50 or later.
CVE-2017-2216 affects all users of WordPress Download Manager versions prior to 2.9.50.
CVE-2017-2216 allows remote attackers to inject arbitrary web scripts or HTML into vulnerable sites.
Versions of WordPress Download Manager prior to 2.9.50 are vulnerable to CVE-2017-2216.