First published: Fri Mar 25 2022(Updated: )
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_url, &download_categories.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Download Manager Pro | <1.68.6 |
Update to 1.68.6 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25606 is considered a high severity vulnerability due to its potential for authenticated stored cross-site scripting attacks.
To mitigate CVE-2022-25606, update the WP-DownloadManager plugin to a version later than 1.68.6.
The vulnerable versions of the WP-DownloadManager plugin are 1.68.6 and earlier.
CVE-2022-25606 identifies multiple authenticated stored cross-site scripting (XSS) vulnerabilities.
The vulnerable parameters associated with CVE-2022-25606 include &download_path, &download_path_url, &download_page_url, and &download_categories.