CVE-2022-45836
WordPress Download Manager Plugin <= 3.2.59 is vulnerable to Cross Site Scripting (XSS)
Record summary
CVE-2022-45836 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.
Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Download ManagerBrowse W3 Eden, Inc. / Download ManagerDefault status: unaffected | CVE List | Through 3.2.59 | affected |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Download Manager <= 3.2.59 - Reflected XSS
W3 Eden, Inc. Download Manager plugin <= 3.2.59 contains a reflected cross-site scripting caused by insufficient input sanitization, letting attackers execute scripts in the context of the victim's browser, exploit requires attacker to craft a malicious link.
Impact
Attackers can execute arbitrary scripts in the victim's browser, potentially leading to session hijacking or defacement.
Remediation
Update to the latest version of the plugin where the vulnerability is fixed.
Source: ProjectDiscovery