CVE-2022-2168: Download Manager < 3.2.44 - Reflected Cross-Site Scripting
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2168?
CVE-2022-2168 is a vulnerability in the Download Manager WordPress plugin before version 3.2.44 that allows for Reflected Cross-Site Scripting.
What is the severity of CVE-2022-2168?
CVE-2022-2168 has a severity rating of medium with a CVSS score of 6.1.
How does CVE-2022-2168 affect the Download Manager WordPress plugin?
CVE-2022-2168 affects the Download Manager WordPress plugin before version 3.2.44 by allowing for Reflected Cross-Site Scripting.
How can I fix CVE-2022-2168?
To fix CVE-2022-2168, update the Download Manager WordPress plugin to version 3.2.44 or later.
Which CWE category does CVE-2022-2168 belong to?
CVE-2022-2168 belongs to CWE category 79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').