Record summary

CVE-2022-45836 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.

Description

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 10, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 3.2.59affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Download Manager <= 3.2.59 - Reflected XSS

W3 Eden, Inc. Download Manager plugin <= 3.2.59 contains a reflected cross-site scripting caused by insufficient input sanitization, letting attackers execute scripts in the context of the victim's browser, exploit requires attacker to craft a malicious link.

Impact

Attackers can execute arbitrary scripts in the victim's browser, potentially leading to session hijacking or defacement.

Remediation

Update to the latest version of the plugin where the vulnerability is fixed.

AuthorsShivam Kamboj
Template tagscvecve2022wordpresswp-pluginxssdownload-managerwpdmwp

Source: ProjectDiscovery

References

2