CVE-2019-15889 | download-manager Plugin up to 2.9.93 on WordPress Category orderby/search[publish_date] cross site scripting (ID 154356 / EDB-47350)
A vulnerability classified as problematic has been found in download-manager Plugin up to 2.9.93 on WordPress. Affected is an unknown function of the component Category Handler. This manipulation of the argument orderby/search[publish_date] as part of Parameter causes cross site scripting.
This vulnerability is tracked as CVE-2019-15889. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is recommended to upgrade the affected component.