First published: Fri Sep 07 2018(Updated: )
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webdesi9 File Manager | =2.9 | |
Filemanagerpro File Manager Wordpress | =2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16363 is a vulnerability in the mndpsingh287 File Manager plugin V2.9 for WordPress that allows for XSS attacks.
CVE-2018-16363 works by exploiting the lang parameter in a wp-admin/admin.php?page=wp_file_manager request to execute XSS attacks.
The severity of CVE-2018-16363 is medium with a CVSS score of 5.4.
To fix CVE-2018-16363, update the mndpsingh287 File Manager plugin to version 2.9 or higher.
You can find more information about CVE-2018-16363 on the following websites: http://blog.51cto.com/010bjsoft/2171087, https://plugins.trac.wordpress.org/changeset/1936043, and https://wordpress.org/support/topic/security-concern-6/#post-10655739.