CVE · High

CVE-2022-0828 — Download Manager [download-manager] < 3.2.39

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0828 Download Manager [download-manager] < 3.2.39 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) High 7.5 < 3.2.39 3.2.39 2022-03-16

CVE-2022-0828

The Download Manager plugin prior to version 3.2.39 relies on PHP's uniqid function to create master keys for downloads, which produces predictable values that attackers can efficiently brute force. This vulnerability enables unauthorized users to bypass role-based access controls and password protections to obtain direct download access with moderate computational effort.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.