SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-2392

The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.

MEDIUM 6.5EPSS 1.10%

Does this matter?

Lower severity and a low EPSS score (1.10%). Track it; it rarely justifies an emergency change on its own.

Description

The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.10% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-552
Affected
lana/lana downloads manager
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.