CVE-2018-5213

CVE: CVE-2018-5213
Published: 2018-01-04T18:29Z
Vendor: simple_download_monitor_project
Products: simple_download_monitor
Versions: 3.5.4,
Description Language: en
Description: The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.
References:
https://github.com/Arsenal21/simple-download-monitor/commit/8ab8b9166bc87feba26a1573cf595af48eff7805
https://github.com/Arsenal21/simple-download-monitor/issues/27
https://github.com/d4wner/Vulnerabilities-Report/blob/master/simple-download-monitor.md
https://wordpress.org/support/topic/stored-xss-bug-at-the-latest-version-of-simple-download-monitor/