CVE-2024-8444: Download Manager < 3.3.00 - Contributor+ Stored XSS
Published Oct 30, 2024
·Updated
The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.
Affected Software
1 affected component
WordPress Download Manager<3.3.00
Event History
Oct 30, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-8444?
CVE-2024-8444 is classified as a cross site scripting (XSS) vulnerability with a significant impact on user data integrity.
2
How do I fix CVE-2024-8444?
To fix CVE-2024-8444, update the Download Manager WordPress plugin to version 3.3.00 or later.
3
What versions are affected by CVE-2024-8444?
CVE-2024-8444 affects all versions of the Download Manager WordPress plugin prior to version 3.3.00.
4
What type of vulnerability is CVE-2024-8444?
CVE-2024-8444 is a cross site scripting (XSS) vulnerability due to improper sanitization of shortcode parameters.
5
Can CVE-2024-8444 be exploited remotely?
Yes, CVE-2024-8444 can potentially be exploited remotely by attackers through specially crafted input to the affected plugin.