Cross-Site Request Forgery Vulnerability in WP-DownloadManager Plugin for WordPress
CVE-2013-2697
Currently unrated
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP-DownloadManager plugin for WordPress, specifically in versions prior to 1.61. This vulnerability allows remote attackers to exploit user authentication and potentially send requests that include malicious XSS sequences. Such attacks could lead to unauthorized actions being performed on behalf of legitimate users within the affected WordPress environments, compromising the security and integrity of the site.
References
Timeline
Vulnerability Reserved
Vulnerability published