Cross-Site Request Forgery Vulnerability in WP-DownloadManager Plugin for WordPress
CVE-2013-2697

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
19 April 2013

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP-DownloadManager plugin for WordPress, specifically in versions prior to 1.61. This vulnerability allows remote attackers to exploit user authentication and potentially send requests that include malicious XSS sequences. Such attacks could lead to unauthorized actions being performed on behalf of legitimate users within the affected WordPress environments, compromising the security and integrity of the site.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.