First published: Mon Aug 22 2022(Updated: )
The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Download Manager | <3.2.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2362 is considered to have a medium severity due to the potential for bypassing IP-based access restrictions.
To fix CVE-2022-2362, update the Download Manager WordPress plugin to version 3.2.50 or later.
CVE-2022-2362 can be exploited to bypass download restrictions based on IP addresses, potentially allowing unauthorized access to downloads.
Versions of the Download Manager WordPress plugin prior to 3.2.50 are affected by CVE-2022-2362.
Yes, regular users with knowledge of HTTP headers can potentially exploit CVE-2022-2362 to bypass restrictions.