Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-56192
HistoryJul 19, 2022 - 12:00 a.m.

WordPress Download Manager plugin跨站脚本漏洞

2022-07-1900:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
wordpress
download manager plugin
cross-site scripting
vulnerability
php
history dashboard
wordpress foundation

EPSS

0.001

Percentile

40.2%

WordPress and WordPress plugin are both products of the WordPress Foundation. WordPress is a blogging platform developed using the PHP language. WordPress plugin is an application plugin. A cross-site scripting vulnerability exists in versions of the WordPress Download Manager plugin prior to 3.2.44, which stems from the plugin’s failure to The vulnerability is caused by the plugin’s failure to escape the generated URs before exporting them back to the properties of the history dashboard.

EPSS

0.001

Percentile

40.2%