CVE-2019-17239: Wpfactory Download Plugins And Themes From Dashboard

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.

Affected products

  • Wpfactory Download Plugins And Themes From Dashboard: up to and including 1.5.0

Published 2019-10-07. Last modified 2026-06-17.