Input validation vulnerability in Download Manager 3.2.70

The Download Manager plugin for WordPress, up to version 3.2.70, is vulnerable to a type of attack called Stored Cross-Site Scripting. In this attack, an attacker with contributor-level or higher permissions can inject malicious scripts into pages. When a user visits the page, the scripts will be executed, potentially exposing the user to malicious activity. This is caused by the plugin not properly sanitizing and escaping user input.

Detected in:

Download Manager fixed vulnerable versions: >= * <= 3.2.70
Download Manager Pro fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.