Download Manager <= 2.8.7 - Privilege Escalation

2016-01-19 00:00
James Golovich

Strategic Overview

Status
Patched in 2.8.8
Affected PluginDownload Manager
Affected Version< 2.8.8
CVSS6.5Medium
CVEN/A
View all Download Manager vulnerabilities

Vulnerability Overview

The Download Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.8.7. This is due to unchecked use of the extract() function which makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit user metadata, including their role.

Technical Analysis

REMEDIATION: Update to version 2.8.8, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C