CVE · High

CVE-2022-2431 — Download Manager [download-manager] < 3.2.51

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2431 Download Manager [download-manager] < 3.2.51 External Control of File Name or Path High 8.8 < 3.2.51 3.2.51 2022-07-27

CVE-2022-2431

The Download Manager plugin for WordPress through version 3.2.50 contains an arbitrary file deletion vulnerability in the deleteFiles() function within the Packages.php file. When a download post is deleted, the function fails to properly validate file paths and types, allowing contributors and higher-level users to delete arbitrary files by supplying a malicious path through the file[files] parameter. Attackers could exploit this to remove critical files like wp-config.php, effectively resetting the WordPress installation and enabling remote code execution.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.