CVE-2013-2697

NONE EPSS 57.1%
Published Apr 19, 201313y ago · Modified Jun 16, 20262w ago
Find Similar
Published Apr 19, 2013 13y ago
Last Modified Jun 16, 2026 2w ago

Description

Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Threat Intelligence

EPSS Exploit Probability
57.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-352 Cross-Site Request Forgery (CSRF) Authentication

Affected Products 7

VendorProductVersionRange
lesterchanwp-downloadmanager* ≤1.60
lesterchanwp-downloadmanager1.00any
lesterchanwp-downloadmanager1.30any
lesterchanwp-downloadmanager1.31any
lesterchanwp-downloadmanager1.40any
lesterchanwp-downloadmanager1.50any
wordpresswordpress*any

References 2

  • secunia.com http://secunia.com/advisories/52863
    Vendor Advisory
  • wordpress.org http://wordpress.org/extend/plugins/wp-downloadmanager/changelog/

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.