CVE-2022-0828

HIGH

WordPress Plugin <3.2.34 - Code Injection

Title source: llm
STIX 2.1

Description

The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 58.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-338
Status published
Products (1)
w3eden/download_manager < 3.2.34
Published Apr 11, 2022
Tracked Since Feb 18, 2026