CVE-2017-18032 | download-manager Plugin up to 2.9.51 on WordPress wp-admin/admin-ajax.php wpdm_generate_password ID cross site scripting (ID 800847)
A vulnerability was found in download-manager Plugin up to 2.9.51 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function wpdm_generate_password of the file wp-admin/admin-ajax.php. The manipulation of the argument ID as part of Parameter leads to cross site scripting.
This vulnerability is known as CVE-2017-18032. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.