CVE-2021-24773: WordPress Download Manager < 3.2.16 - Admin+ Stored Cross-Site Scripting
Published Nov 1, 2021
·Updated
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfilteredhtml capability is disallowed
Affected Software
2 affected components
Wpdownloadmanager Wordpress Download Manager Wordpress<3.2.16
W3eden Download Manager Wordpress<3.2.16
Event History
Nov 1, 2021
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24773?
CVE-2021-24773 has been classified as a high severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2021-24773?
To mitigate CVE-2021-24773, update the WordPress Download Manager plugin to version 3.2.16 or later.
3
Who is affected by CVE-2021-24773?
CVE-2021-24773 affects users of the WordPress Download Manager plugin prior to version 3.2.16.
4
What type of attack does CVE-2021-24773 enable?
CVE-2021-24773 allows high privilege users to perform cross-site scripting (XSS) attacks.
5
Is unfiltered_html capability a factor in CVE-2021-24773?
CVE-2021-24773 can be exploited regardless of whether the unfiltered_html capability is disallowed for users.