The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
W3eden
W3eden download Manager |
|
CPEs | cpe:2.3:a:w3eden:download_manager:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpdownloadmanager
Wpdownloadmanager wordpress Download Manager |
W3eden
W3eden download Manager |

Status: PUBLISHED
Assigner: mitre
Published: 2019-09-03T17:07:01
Updated: 2024-08-05T01:03:32.214Z
Reserved: 2019-09-03T00:00:00
Link: CVE-2019-15889

No data.

Status : Modified
Published: 2019-09-03T18:15:12.670
Modified: 2025-03-21T16:07:09.227
Link: CVE-2019-15889

No data.