First published: Mon Apr 15 2019(Updated: )
There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webdesi9 File Manager | =3.0 | |
Filemanagerpro File Manager Wordpress | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability has a severity of medium.
The vulnerability allows for cross-site scripting (XSS) attacks via the page=wp_file_manager_root public_path parameter.
The vulnerability affects version 3.0 of the mndpsingh287 File Manager plugin for WordPress.
Yes, a patch is available to fix the vulnerability. Please refer to the official plugin documentation or contact the plugin developer for the patch.
You can find more information about the vulnerability in the references provided: [reference 1](https://ansawaf.blogspot.com/2019/04/file-manager-plugin-wordpress-plugin.html), [reference 2](https://wordpress.org/plugins/wp-file-manager/#developers), [reference 3](https://wpvulndb.com/vulnerabilities/9614).