Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-16363
Description:The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-16363
http://blog.51cto.com/010bjsoft/2171087
https://plugins.trac.wordpress.org/changeset/1936043
https://wpvulndb.com/vulnerabilities/9126




© 1998-2025 E-Soft Inc. All rights reserved.