Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-2926


The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory


Published

2022-09-26T13:15:10.577

Last Modified

2025-05-21T17:15:53.663

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe download_manager < 3.2.55 Yes

References