Title: Persistant XSS
Last modified: August 31, 2016

---

# Persistant XSS

 *  [InternalError503](https://wordpress.org/support/users/internalerror503/)
 * (@internalerror503)
 * [10 years, 7 months ago](https://wordpress.org/support/topic/persistant-xss/)
 * Not sure if your aware as i checked you git hub but couldn’t see anything, The
   current version 1.6.7 is exploitable [https://www.intelligentexploit.com/view-details.html?id=22164](https://www.intelligentexploit.com/view-details.html?id=22164)
 * Just thought i would let you know in-case.
 * [https://wordpress.org/plugins/wp-downloadmanager/](https://wordpress.org/plugins/wp-downloadmanager/)

Viewing 1 replies (of 1 total)

 *  Plugin Author [Lester Chan](https://wordpress.org/support/users/gamerz/)
 * (@gamerz)
 * [10 years, 7 months ago](https://wordpress.org/support/topic/persistant-xss/#post-6988246)
 * Hmm not sure if the report is valid.
 * 1. Only admins can add a download and the field is open ended because there might
   be somecases where user need to have JS tracking
    2. If going by this logic, 
   XSS also is valid in WordPress post because if if I am an admin, I can post JS
   within a post content.
 * But anyway, I added wp_kses_post() to better sanatize the fields [https://github.com/lesterchan/wp-downloadmanager/commit/302557a3a2819f8a5f4deb22f02e7aa00116d6d4](https://github.com/lesterchan/wp-downloadmanager/commit/302557a3a2819f8a5f4deb22f02e7aa00116d6d4).
   It will be released in the next version

Viewing 1 replies (of 1 total)

The topic ‘Persistant XSS’ is closed to new replies.

 * ![](https://ps.w.org/wp-downloadmanager/assets/icon.svg?rev=978031)
 * [WP-DownloadManager](https://wordpress.org/plugins/wp-downloadmanager/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wp-downloadmanager/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wp-downloadmanager/)
 * [Active Topics](https://wordpress.org/support/plugin/wp-downloadmanager/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wp-downloadmanager/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wp-downloadmanager/reviews/)

## Tags

 * [exploit](https://wordpress.org/support/topic-tag/exploit/)
 * [xss](https://wordpress.org/support/topic-tag/xss/)

 * 1 reply
 * 2 participants
 * Last reply from: [Lester Chan](https://wordpress.org/support/users/gamerz/)
 * Last activity: [10 years, 7 months ago](https://wordpress.org/support/topic/persistant-xss/#post-6988246)
 * Status: not resolved