CVE-2022-2926

medium

Description

The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory

References

https://wpscan.com/vulnerability/2a440e1a-a7e4-4106-839a-d93895e16785

Details

Source: Mitre, NVD

Published: 2022-09-26

Updated: 2022-09-28

Risk Information

CVSS v2

Base Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.9

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Severity: Medium