First published: Mon Feb 21 2022(Updated: )
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Download Manager | <3.2.34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-25069.
CVE-2021-25069 has a severity rating of 8.8 (high).
The affected software by CVE-2021-25069 is the Download Manager WordPress plugin before version 3.2.34.
CVE-2021-25069 can lead to a SQL injection and a Reflected Cross-Site Scripting issue.
To fix CVE-2021-25069, upgrade the Download Manager WordPress plugin to version 3.2.34 or later.