CVE · High

CVE-2022-2362 — Download Manager [download-manager] < 3.2.50

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2362 Download Manager [download-manager] < 3.2.50 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.5 < 3.2.50 3.2.50 2022-08-01

CVE-2022-2362

The Download Manager WordPress plugin through version 3.2.49 contains a flaw in how it identifies visitor IP addresses, enabling unauthenticated attackers to forge their IP and bypass file access restrictions that rely on IP-based protections. An attacker exploiting this weakness could gain unauthorized access to files that should be blocked based on IP filtering rules.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.