CVE-2013-2697
NONE EPSS 57.1%
Published Apr 19, 201313y ago · Modified Jun 16, 20262w ago
Published Apr 19, 2013 13y ago
Last Modified Jun 16, 2026 2w ago
Description
Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Threat Intelligence
EPSS Exploit Probability
57.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-352 Cross-Site Request Forgery (CSRF) Authentication
Affected Products 7
| Vendor | Product | Version | Range |
|---|---|---|---|
| lesterchan | wp-downloadmanager | * | ≤1.60 |
| lesterchan | wp-downloadmanager | 1.00 | any |
| lesterchan | wp-downloadmanager | 1.30 | any |
| lesterchan | wp-downloadmanager | 1.31 | any |
| lesterchan | wp-downloadmanager | 1.40 | any |
| lesterchan | wp-downloadmanager | 1.50 | any |
| wordpress | wordpress | * | any |
References 2
- secunia.com http://secunia.com/advisories/52863
- wordpress.org http://wordpress.org/extend/plugins/wp-downloadmanager/changelog/
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.