What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
Explanation of Vulnerability in Simple Terms
The Download Manager WordPress plugin version 3.2.48 and earlier is vulnerable to cross-site request forgery (CSRF). An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions within the plugin without the administrator's knowledge or consent. This could result in unauthorized changes to plugin settings or data.
What an attacker can do
Trick a logged-in admin into performing unwanted actions in the plugin via a malicious webpage.
Potential impact on your site
Unauthorized changes to Download Manager settings or data if an admin visits a malicious link while logged in.
Conditions required to exploit
Admin must visit attacker's webpage while logged into WordPress. Attack requires high complexity to succeed.
Key dates
External resources
Related vulnerabilities