WordPress File Manager < 3.0 - Cross-Site Scripting
CVE-2018-16363
Verified
Description
WordPress File Manager plugin before 3.0 is vulnerable to authenticated reflected cross-site scripting (XSS) via the lang parameter in the admin dashboard. The parameter is directly echoed into a JavaScript context without proper sanitization.
Severity
Medium
Published Date
February 4, 2026
Template Author
shivam kamboj
CVE-2018-16363.yaml