CVE · Medium

CVE-2019-15889 — Download Manager [download-manager] < 2.9.94

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-15889 Download Manager [download-manager] < 2.9.94 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.9.94 2.9.94 2019-04-13

CVE-2019-15889

The Download Manager plugin before version 2.9.94 contains a reflected cross-site scripting vulnerability in its Category Short-code feature, which processes user input through the orderby parameter without proper sanitization. An attacker can inject malicious JavaScript by manipulating the orderby parameter with payloads such as "> followed by script tags, causing the payload to execute in a user's browser. The same vulnerability also exists in the Advanced Search functionality, allowing for similar exploitation through unsanitized input handling.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.