First published: Wed Oct 30 2024(Updated: )
The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Download Manager | <3.3.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8444 is classified as a cross site scripting (XSS) vulnerability with a significant impact on user data integrity.
To fix CVE-2024-8444, update the Download Manager WordPress plugin to version 3.3.00 or later.
CVE-2024-8444 affects all versions of the Download Manager WordPress plugin prior to version 3.3.00.
CVE-2024-8444 is a cross site scripting (XSS) vulnerability due to improper sanitization of shortcode parameters.
Yes, CVE-2024-8444 can potentially be exploited remotely by attackers through specially crafted input to the affected plugin.