Cross-Site Scripting Vulnerability in Simple Download Monitor by WordPress
CVE-2018-5213
5.4MEDIUM
Summary
The Simple Download Monitor plugin for WordPress is susceptible to a Cross-Site Scripting (XSS) vulnerability that affects the 'sdm_upload' parameter during an edit action in the wp-admin/post.php file. This flaw can allow attackers to inject malicious scripts that execute in users' browsers, compromising the security of web applications utilizing the plugin. It's essential for site administrators to update to version 3.5.4 or later to mitigate this risk and safeguard user data.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved