Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-2636 | Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 14 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lesterchan
Lesterchan wp-downloadmanager |
|
| CPEs | cpe:2.3:a:lester_chan:wp-downloadmanager:1.00:*:*:*:*:*:*:* cpe:2.3:a:lester_chan:wp-downloadmanager:1.30:*:*:*:*:*:*:* cpe:2.3:a:lester_chan:wp-downloadmanager:1.31:*:*:*:*:*:*:* cpe:2.3:a:lester_chan:wp-downloadmanager:1.40:*:*:*:*:*:*:* cpe:2.3:a:lester_chan:wp-downloadmanager:1.50:*:*:*:*:*:*:* |
cpe:2.3:a:lesterchan:wp-downloadmanager:*:*:*:*:*:*:*:* cpe:2.3:a:lesterchan:wp-downloadmanager:1.00:*:*:*:*:*:*:* cpe:2.3:a:lesterchan:wp-downloadmanager:1.30:*:*:*:*:*:*:* cpe:2.3:a:lesterchan:wp-downloadmanager:1.31:*:*:*:*:*:*:* cpe:2.3:a:lesterchan:wp-downloadmanager:1.40:*:*:*:*:*:*:* cpe:2.3:a:lesterchan:wp-downloadmanager:1.50:*:*:*:*:*:*:* |
| Vendors & Products |
Lester Chan
Lester Chan wp-downloadmanager |
Lesterchan
Lesterchan wp-downloadmanager |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: flexera
Published:
Updated: 2024-09-16T17:48:19.970Z
Reserved: 2013-03-26T00:00:00Z
Link: CVE-2013-2697
No data.
Status : Deferred
Published: 2013-04-19T11:44:26.747
Modified: 2026-01-14T19:07:51.600
Link: CVE-2013-2697
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD