CVE-2022-2357

HIGH

WSM Downloader <1.4.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/42499b84-684e-42e1-b7f0-de206d4da553

Scores

CVSS v3 7.5
EPSS 0.0116
EPSS Percentile 62.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-552
Status published
Products (1)
wsm_downloader_project/wsm_downloader < 1.4.0
Published Aug 08, 2022
Tracked Since Feb 18, 2026