First published: Fri Dec 20 2024(Updated: )
The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Download Manager | <3.3.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10706 has a moderate severity rating due to its potential for Stored Cross-Site Scripting attacks.
To fix CVE-2024-10706, update the WordPress Download Manager plugin to version 3.3.03 or later.
CVE-2024-10706 affects high privilege users such as administrators using the vulnerable Download Manager WordPress plugin.
CVE-2024-10706 allows for Stored Cross-Site Scripting (XSS) attacks due to improper sanitization of settings.
Versions of the WordPress Download Manager plugin prior to 3.3.03 are vulnerable to CVE-2024-10706.