CVE-2018-16363
Last modified
CVE-2018-16363 is a vulnerability of currently unknown severity. The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php.. EPSS estimates a 1.38% chance of exploitation in the next 30 days.
Description
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Filemanagerpro | File Manager | 2.9 |
References
- http://blog.51cto.com/010bjsoft/2171087Exploit, Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/1936043Patch, Third Party Advisory
- https://wordpress.org/support/topic/security-concern-6/#post-10655739Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9126Patch, Third Party Advisory
- http://blog.51cto.com/010bjsoft/2171087Exploit, Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/1936043Patch, Third Party Advisory
- https://wordpress.org/support/topic/security-concern-6/#post-10655739Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9126Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16363?
How severe is CVE-2018-16363?
How do I fix CVE-2018-16363?
Are you affected by CVE-2018-16363?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
