Unrated severityOSV Advisory· Published Jan 4, 2018· Updated Aug 5, 2024
CVE-2018-5213
CVE-2018-5213
Description
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/Arsenal21/simple-download-monitor/commit/8ab8b9166bc87feba26a1573cf595af48eff7805mitrex_refsource_MISC
- github.com/Arsenal21/simple-download-monitor/issues/27mitrex_refsource_MISC
- github.com/d4wner/Vulnerabilities-Report/blob/master/simple-download-monitor.mdmitrex_refsource_MISC
- wordpress.org/support/topic/stored-xss-bug-at-the-latest-version-of-simple-download-monitor/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.