CVE-2024-8284: Download Manager <= 3.2.98 - Admin+ Stored XSS
Published May 15, 2025
·Updated
The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
2 affected components
WordPress Download Manager<3.2.99
W3eden Download Manager Wordpress<3.2.99
Event History
May 15, 2025
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-8284?
CVE-2024-8284 has a high severity rating due to its potential for Cross-Site Scripting attacks.
2
How do I fix CVE-2024-8284?
To fix CVE-2024-8284, update the Download Manager WordPress plugin to version 3.2.99 or later.
3
Who is affected by CVE-2024-8284?
CVE-2024-8284 affects users of the Download Manager WordPress plugin prior to version 3.2.99.
4
What types of attacks can CVE-2024-8284 facilitate?
CVE-2024-8284 can facilitate Cross-Site Scripting attacks by allowing high privilege users to execute malicious scripts.
5
What WordPress plugin is associated with CVE-2024-8284?
CVE-2024-8284 is associated with the Download Manager WordPress plugin.