CVE · Medium

CVE-2021-24773 — Download Manager [download-manager] < 3.2.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24773 Download Manager [download-manager] < 3.2.16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.2.16 3.2.16 2021-09-29

CVE-2021-24773

The Download Manager plugin prior to version 3.2.16 fails to properly escape certain Download configuration parameters during output, creating an opportunity for administrators and other high-privileged users to inject malicious scripts even in environments where the unfiltered_html capability has been restricted.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.