CVE-2024-10706: Download Manager < 3.3.03 - Admin+ Stored XSS
The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10706?
CVE-2024-10706 has a moderate severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-10706?
To fix CVE-2024-10706, update the WordPress Download Manager plugin to version 3.3.03 or later.
Who is affected by CVE-2024-10706?
CVE-2024-10706 affects high privilege users such as administrators using the vulnerable Download Manager WordPress plugin.
What kind of attack does CVE-2024-10706 allow?
CVE-2024-10706 allows for Stored Cross-Site Scripting (XSS) attacks due to improper sanitization of settings.
What versions of the WordPress Download Manager are vulnerable to CVE-2024-10706?
Versions of the WordPress Download Manager plugin prior to 3.3.03 are vulnerable to CVE-2024-10706.