Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2024-10706

The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

No technical information available.

No CWE or OWASP classifications available.