First published: Mon Jun 13 2022(Updated: )
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.
Credit: security@wordfence.com security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Download Manager | <=3.2.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1985 is categorized as a reflected Cross-Site Scripting vulnerability with a medium severity rating.
To remediate CVE-2022-1985, update the Download Manager Plugin for WordPress to version 3.2.43 or later.
CVE-2022-1985 affects versions of the Download Manager Plugin for WordPress up to and including 3.2.42.
CVE-2022-1985 is a reflected Cross-Site Scripting vulnerability caused by insufficient input sanitization and output escaping.
The vulnerability CVE-2022-1985 specifically affects the 'frameid' parameter found in the shortcode-iframe.php file.