CVE-2022-4476

Severity
5.4MEDIUM
EPSS
0.3%
top 51.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16

Description

The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

CVEListV5unknown/download_manager< 3.2.62

🔴Vulnerability Details

2
GHSA
GHSA-x554-cpg3-r3hr: The Download Manager WordPress plugin before 32023-01-16
CVEList
Download Manager < 3.2.62 - Contributor+ Stored XSS2023-01-16