CVE-2018-16967: XSS
There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wpfilemanagerroot publicpath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability severity of CVE-2018-16967?
The vulnerability has a severity of medium.
How does the CVE-2018-16967 vulnerability affect the mndpsingh287 File Manager plugin for WordPress?
The vulnerability allows for cross-site scripting (XSS) attacks via the page=wp_file_manager_root public_path parameter.
Which version of the mndpsingh287 File Manager plugin for WordPress is affected by CVE-2018-16967?
The vulnerability affects version 3.0 of the mndpsingh287 File Manager plugin for WordPress.
Is there a patch available to fix CVE-2018-16967?
Yes, a patch is available to fix the vulnerability. Please refer to the official plugin documentation or contact the plugin developer for the patch.
Where can I find more information about CVE-2018-16967?
You can find more information about the vulnerability in the references provided: [reference 1](https://ansawaf.blogspot.com/2019/04/file-manager-plugin-wordpress-plugin.html), [reference 2](https://wordpress.org/plugins/wp-file-manager/#developers), [reference 3](https://wpvulndb.com/vulnerabilities/9614).