First published: Fri Mar 18 2022(Updated: )
Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 versions.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Download Manager Pro | <1.68.7 |
Update to 1.68.7 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44760 has a high severity level due to its nature as an authenticated reflected cross-site scripting (XSS) vulnerability.
To fix CVE-2021-44760, upgrade the WP-DownloadManager plugin to version 1.68.7 or higher.
CVE-2021-44760 affects users of the WP-DownloadManager plugin versions 1.68.6 and earlier installed on WordPress.
The impact of CVE-2021-44760 includes the potential for attackers to execute arbitrary JavaScript code in the context of the user’s session.
CVE-2021-44760 is classified as a reflected cross-site scripting (XSS) vulnerability that requires authentication to exploit.