CVE-2022-2436
The Download Manager plugin for WordPress contains a deserialization vulnerability in versions up to 3.2.49 affecting the 'file[package_dir]' parameter. Authenticated attackers holding contributor-level permissions or higher can exploit this by uploading a malicious file and using a PHAR wrapper to deserialize untrusted data and instantiate arbitrary PHP objects, potentially executing malicious code if a suitable POP chain exists on the target system.
Based on public CVE data (MITRE/NVD).