CVE Database /
CVE-2022-0828
CVE · High
CVE-2022-0828 — Download Manager [download-manager] < 3.2.39
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-0828
|
Download Manager [download-manager] < 3.2.39 |
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) |
High
7.5
|
< 3.2.39
|
3.2.39 |
2022-03-16 |
—
|
CVE-2022-0828
The Download Manager plugin prior to version 3.2.39 relies on PHP's uniqid function to create master keys for downloads, which produces predictable values that attackers can efficiently brute force. This vulnerability enables unauthorized users to bypass role-based access controls and password protections to obtain direct download access with moderate computational effort.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings