CVE-2019-15889: XSS
Published Sep 3, 2019
·Updated
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publishdate] parameter.
Affected Software
2 affected components
Wpdownloadmanager Wordpress Download Manager Wordpress<2.9.94
W3eden Download Manager Wordpress<2.9.94
Remediation
Event History
Sep 3, 2019
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2019-15889?
CVE-2019-15889 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-15889?
To fix CVE-2019-15889, update the WordPress Download Manager plugin to version 2.9.94 or later.
3
What is the impact of CVE-2019-15889?
The impact of CVE-2019-15889 allows an attacker to inject malicious scripts into web pages viewed by users.
4
Who is affected by CVE-2019-15889?
CVE-2019-15889 affects users of the WordPress Download Manager plugin versions prior to 2.9.94.
5
What type of vulnerability is CVE-2019-15889?
CVE-2019-15889 is a cross-site scripting (XSS) vulnerability that can be exploited through crafted shortcode parameters.