dwnldr < 1.01 - Cross-Site Scripting
mediumThe dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header.
- CVSS:
- 6.1
- Affected:
- up to 1.0
- Fixed in:
- 1.01
- Disclosed:
- Jul 18, 2016
plugin
1 known security issue reported for the Dwnldr WordPress plugin. Most recent disclosed Jul 18, 2016.
Running Dwnldr on your site? Check whether your installed version is affected.
Scan your site freeThe dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free