Description
WordPress Plugin SS Downloads is prone to cross-site request forgery and information disclosure vulnerabilities. An attacker can exploit these issues to perform certain administrative actions and gain unauthorized access to the affected application, or to obtain sensitive information that may help in launching further attacks. WordPress Plugin SS Downloads version 1.4.3 is vulnerable; prior versions may also be affected.
Remediation
Update to the latest version
References
Related Vulnerabilities
ownCloud Improper Restriction of XML External Entity Reference Vulnerability (CVE-2014-2052)
MediaWiki Improper Input Validation Vulnerability (CVE-2013-6453)
WordPress Plugin User Registration, Login & Landing Pages-LeadMagic Cross-Site Scripting (1.2.7)
WordPress Plugin TC Custom JavaScript Cross-Site Scripting (1.2.1)
WordPress Plugin Starbox-the Author Box for Humans Cross-Site Scripting (3.0.8)