Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.
References
Configurations
Configuration 1 (hide)
|
History
21 Mar 2025, 16:07
Type | Values Removed | Values Added |
---|---|---|
First Time |
W3eden download Manager
W3eden |
|
CPE | cpe:2.3:a:wpdownloadmanager:wordpress_download_manager:2.5.7:*:*:*:*:wordpress:*:* cpe:2.3:a:wpdownloadmanager:wordpress_download_manager:2.5.3:*:*:*:*:wordpress:*:* cpe:2.3:a:wpdownloadmanager:wordpress_download_manager:*:*:*:*:*:wordpress:*:* cpe:2.3:a:wpdownloadmanager:wordpress_download_manager:2.5.2:*:*:*:*:wordpress:*:* cpe:2.3:a:wpdownloadmanager:wordpress_download_manager:2.5.1:*:*:*:*:wordpress:*:* cpe:2.3:a:wpdownloadmanager:wordpress_download_manager:2.5.6:*:*:*:*:wordpress:*:* cpe:2.3:a:wpdownloadmanager:wordpress_download_manager:2.5.0:*:*:*:*:wordpress:*:* cpe:2.3:a:wpdownloadmanager:wordpress_download_manager:2.5.5:*:*:*:*:wordpress:*:* |
cpe:2.3:a:w3eden:download_manager:2.5.5:*:*:*:*:wordpress:*:* cpe:2.3:a:w3eden:download_manager:2.5.7:*:*:*:*:wordpress:*:* cpe:2.3:a:w3eden:download_manager:2.5.1:*:*:*:*:wordpress:*:* cpe:2.3:a:w3eden:download_manager:2.5.2:*:*:*:*:wordpress:*:* cpe:2.3:a:w3eden:download_manager:*:*:*:*:*:wordpress:*:* cpe:2.3:a:w3eden:download_manager:2.5.4:*:*:*:*:wordpress:*:* cpe:2.3:a:w3eden:download_manager:2.5.0:*:*:*:*:wordpress:*:* cpe:2.3:a:w3eden:download_manager:2.5.6:*:*:*:*:wordpress:*:* cpe:2.3:a:w3eden:download_manager:2.5.3:*:*:*:*:wordpress:*:* |
Information
Published : 2014-02-06 16:10
Updated : 2025-04-11 00:51
NVD link : CVE-2013-7319
Mitre link : CVE-2013-7319
CVE.ORG link : CVE-2013-7319
JSON object : View
Products Affected
w3eden
- download_manager
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')