CVE · High

CVE-2022-45836 — Download Manager [download-manager] < 3.2.60

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-45836 Download Manager [download-manager] < 3.2.60 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.2.60 3.2.60 2022-11-29

CVE-2022-45836

The Download Manager plugin for WordPress contains reflected cross-site scripting vulnerabilities in multiple files including packages-shortcode-toolbar.php, Shortcodes.php, and category-shortcode-toolbar.php located within the src/Package/views/ and src/Category/views/ directories, affecting versions through 3.2.59. The vulnerabilities stem from inadequate sanitization of user input and insufficient escaping of output, allowing unauthenticated attackers to inject malicious scripts that execute when a user visits a specially crafted link. The flaw was remedied in version 3.2.60 or later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.