CVE-2017-2216: XSS
Published Jul 7, 2017
·Updated
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
2 affected components
Wpdownloadmanager Wordpress Download Manager Wordpress<=2.9.49
W3eden Download Manager Wordpress<=2.9.49
Remediation
Patch Available
Patch Available
Event History
Jul 7, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-2216?
CVE-2017-2216 has been classified as a medium severity cross-site scripting vulnerability that affects multiple versions of WordPress Download Manager.
2
How do I fix CVE-2017-2216?
To fix CVE-2017-2216, you should update WordPress Download Manager to version 2.9.50 or later.
3
Who is affected by CVE-2017-2216?
CVE-2017-2216 affects all users of WordPress Download Manager versions prior to 2.9.50.
4
What type of attack does CVE-2017-2216 allow?
CVE-2017-2216 allows remote attackers to inject arbitrary web scripts or HTML into vulnerable sites.
5
What versions of WordPress Download Manager are vulnerable to CVE-2017-2216?
Versions of WordPress Download Manager prior to 2.9.50 are vulnerable to CVE-2017-2216.