First published: Fri Jul 07 2017(Updated: )
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Download Manager | <=2.9.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2217 is classified as a high severity open redirect vulnerability.
To fix CVE-2017-2217, update the WordPress Download Manager plugin to version 2.9.51 or later.
CVE-2017-2217 is caused by improper validation of redirect URLs in the WordPress Download Manager plugin.
Any website using the WordPress Download Manager plugin versions prior to 2.9.51 is affected by CVE-2017-2217.
CVE-2017-2217 can facilitate phishing attacks by allowing attackers to redirect users to arbitrary websites.