Skip to content

Known CVE

WordPress File Manager < 3.0 - Cross-Site Scripting

WordPress File Manager plugin before 3.0 is vulnerable to authenticated reflected cross-site scripting (XSS) via the lang parameter in the admin dashboard. The parameter is directly echoed into a JavaScript context without proper sanitization.

CVE-2018-16363

Medium2018

cve2018 · xss · wp-file-manager · wordpress · wp · authenticated

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website