The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is able to call it and perform Cross-Site Scripting attacks
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
W3eden
W3eden download Manager |
|
CPEs | cpe:2.3:a:w3eden:download_manager:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpdownloadmanager
Wpdownloadmanager wordpress Download Manager |
W3eden
W3eden download Manager |

Status: PUBLISHED
Assigner: WPScan
Published: 2021-12-27T10:33:21
Updated: 2024-08-03T19:49:14.022Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24969

No data.

Status : Modified
Published: 2021-12-27T11:15:09.140
Modified: 2025-03-21T16:07:09.227
Link: CVE-2021-24969

No data.