CVE-2018-16363: XSS
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wpfilemanager request because settransient is used in filefoldermanager.php and there is an echo of lang in lib\wpfilemanager.php.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-16363?
CVE-2018-16363 is a vulnerability in the mndpsingh287 File Manager plugin V2.9 for WordPress that allows for XSS attacks.
How does CVE-2018-16363 work?
CVE-2018-16363 works by exploiting the lang parameter in a wp-admin/admin.php?page=wp_file_manager request to execute XSS attacks.
What is the severity of CVE-2018-16363?
The severity of CVE-2018-16363 is medium with a CVSS score of 5.4.
How can I fix CVE-2018-16363?
To fix CVE-2018-16363, update the mndpsingh287 File Manager plugin to version 2.9 or higher.
Where can I find more information about CVE-2018-16363?
You can find more information about CVE-2018-16363 on the following websites: http://blog.51cto.com/010bjsoft/2171087, https://plugins.trac.wordpress.org/changeset/1936043, and https://wordpress.org/support/topic/security-concern-6/#post-10655739.