Cross-Site Scripting Vulnerability in Simple Download Monitor by WordPress
CVE-2018-5213

5.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
4 January 2018

Summary

The Simple Download Monitor plugin for WordPress is susceptible to a Cross-Site Scripting (XSS) vulnerability that affects the 'sdm_upload' parameter during an edit action in the wp-admin/post.php file. This flaw can allow attackers to inject malicious scripts that execute in users' browsers, compromising the security of web applications utilizing the plugin. It's essential for site administrators to update to version 3.5.4 or later to mitigate this risk and safeguard user data.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.