CVE-2024-3230 Information

Description

The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘download-attachments’ shortcode in all versions up to and including 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Reference

https://www.wordfence.com/threat-intel/vulnerabilities/id/62475d8f-a0f6-45ab-abd0-ad24e1887c91?source=cve https://wordpress.org/plugins/download-attachments/

Share on: