• hrgrgrgfffr645676543

    (@hrgrgrgfffr645676543)


    Hello!

    On my wordpress website the plugin called “CleanTalk” found a problem in your plugin.
    “The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.”

    Please see the attachment below and what solution can you recommend?

    <a href=”https://ibb.co/Z6QDzL65 “>https://ibb.co/Z6QDzL65
    https://ibb.co/4Z2ZRTDN

    Waiting for your feedback.

    Best regards,
    Alex

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Support Nayeem Hyder

    (@nriddhi)

    Hello @hrgrgrgfffr645676543,

    Hope you are well. We are checking the issue. I have already forwarded it to our related team authority regarding the issue. Please kindly check and let me know if you have any more queries.

    Thank you and kind regards

    Plugin Support Nayeem Hyder

    (@nriddhi)

    I have information from our team that, Issue was fixed about a year ago, You can use the latest version without any issue. please kindly check.

    Thank you and regards

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘Problems with the security on website’ is closed to new replies.