6.5
CVSSv2

CVE-2014-9260

Published: 07/08/2017 Updated: 15/08/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The basic_settings function in the download manager plugin for WordPress prior to 2.7.3 allows remote authenticated users to update every WordPress option.

Vulnerable Product Search on Vulmon Subscribe to Product

downloadmanager download manager

Exploits

# Exploit Title: WordPress Download Manager 272 Privilege Escalation # Date: 24-11-2014 # Software Link: wordpressorg/plugins/download-manager/ # Exploit Author: Kacper Szurek # Contact: twittercom/KacperSzurek # Website: securityszurekpl/ # Category: webapps # CVE: CVE-2014-9260 1 Description Every registered user ...