/Vulnerability Library

WordPress File Manager < 3.0 - Cross-Site Scripting

CVE-2018-16363
Verified

Description

WordPress File Manager plugin before 3.0 is vulnerable to authenticated reflected cross-site scripting (XSS) via the lang parameter in the admin dashboard. The parameter is directly echoed into a JavaScript context without proper sanitization.

Severity

Medium

Published Date

February 4, 2026

Template Author

shivam kamboj

CVE-2018-16363.yaml
5.0Severity

CVSS Metrics

References

https://nvd.nist.gov/vuln/detail/CVE-2018-16363https://wpscan.com/vulnerability/65e4849b-6517-400d-884f-65234f58ab0c/https://plugins.trac.wordpress.org/changeset/1936043https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16363