CVE-2022-2367

HIGH

WSM Downloader <1.4.0 - CSRF

Title source: llm
STIX 2.1

Description

The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to the lack of good "link" parameter validation

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/46afb0c6-2d0c-4a20-a9de-48f35ca93f0f

Scores

CVSS v3 7.5
EPSS 0.0056
EPSS Percentile 68.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-639
Status published
Products (1)
wsm_downloader_project/wsm_downloader < 1.4.0
Published Aug 08, 2022
Tracked Since Feb 18, 2026