Bug 2066185 (CVE-2022-25605) - CVE-2022-25605 wordpress: vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6)
Summary: CVE-2022-25605 wordpress: vulnerabilities discovered in WP-DownloadManager Wo...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2022-25605
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2087625 2087626 2087627 2087628
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-03-21 07:25 UTC by Rohit Keshri
Modified: 2022-05-18 06:54 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2022-05-18 06:54:45 UTC
Embargoed:


Attachments (Terms of Use)

Description Rohit Keshri 2022-03-21 07:25:41 UTC
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url.

https://wordpress.org/plugins/wp-downloadmanager/#developers
https://patchstack.com/database/vulnerability/wp-downloadmanager/wordpress-wp-downloadmanager-plugin-1-68-6-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilities

Comment 2 Rohit Keshri 2022-05-18 06:26:59 UTC
Created wordpress tracking bugs for this issue:

Affects: epel-all [bug 2087625]
Affects: fedora-all [bug 2087626]

Comment 3 Rohit Keshri 2022-05-18 06:27:16 UTC
Created wordpress tracking bugs for this issue:

Affects: epel-all [bug 2087627]
Affects: fedora-all [bug 2087628]


Note You need to log in before you can comment on or make changes to this bug.