Record summary

CVE-2022-2168 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Download Manager

CVE List3.2.44 to < 3.2.44affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Download Manager < 3.2.44 - Authenticated Cross-Site ScriptingCVSS 6.1

The WordPress Download Manager plugin before version 3.2.44 does not properly sanitize and escape the user_ids parameter in the stats history dashboard. This allows authenticated attackers to perform Cross-Site Scripting attacks by injecting malicious JavaScript code.

Impact

Authenticated administrators can inject malicious JavaScript via XSS in the user_ids parameter, potentially stealing session cookies or performing unauthorized administrative actions.

Remediation

Update the WordPress Download Manager plugin to version 3.2.44 or later.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2022wpwordpresswp-pluginxssdownload-managerauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:w3eden:download_manager:*:*:*:*:free:wordpress:*:*
Shodan: html:"wp-content/plugins/download-manager/"
FOFA: body="wp-content/plugins/download-manager/"
Google: inurl:"/wp-content/plugins/download-manager/"

Source: ProjectDiscovery

References

2