CVE-2021-25069: WordPress Download Manager < 3.2.34 - Authenticated SQL Injection to Reflected XSS
Published Feb 21, 2022
·Updated
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the packageids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue
Affected Software
2 affected components
Wpdownloadmanager Download Manager Wordpress<3.2.34
W3eden Download Manager Wordpress<3.2.34
Event History
Feb 21, 2022
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-25069.
2
What is the severity of CVE-2021-25069?
CVE-2021-25069 has a severity rating of 8.8 (high).
3
What is the affected software by CVE-2021-25069?
The affected software by CVE-2021-25069 is the Download Manager WordPress plugin before version 3.2.34.
4
What is the impact of CVE-2021-25069?
CVE-2021-25069 can lead to a SQL injection and a Reflected Cross-Site Scripting issue.
5
How can I fix CVE-2021-25069?
To fix CVE-2021-25069, upgrade the Download Manager WordPress plugin to version 3.2.34 or later.