VulnerabilityModified
CVE-2022-2926
The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory
MEDIUM 4.9EPSS 1.46%
Does this matter?
Lower severity and a low EPSS score (1.46%). Track it; it rarely justifies an emergency change on its own.
Description
The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.46% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- adobe/download manager
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/2a440e1a-a7e4-4106-839a-d93895e16785Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/2a440e1a-a7e4-4106-839a-d93895e16785Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.