CVE · High

CVE-2022-2436 — Download Manager [download-manager] < 3.2.71

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2436 Download Manager [download-manager] < 3.2.71 Deserialization of Untrusted Data High 8.8 < 3.2.71 3.2.71 2022-08-17

CVE-2022-2436

The Download Manager plugin for WordPress contains a deserialization vulnerability in versions up to 3.2.49 affecting the 'file[package_dir]' parameter. Authenticated attackers holding contributor-level permissions or higher can exploit this by uploading a malicious file and using a PHAR wrapper to deserialize untrusted data and instantiate arbitrary PHP objects, potentially executing malicious code if a suitable POP chain exists on the target system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.