CVE-2022-2362: Download Manager < 3.2.50 - Bypass IP Address Blocking Restriction
The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTEADDR, which makes it possible to bypass IP-based download blocking restrictions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2362?
CVE-2022-2362 is considered to have a medium severity due to the potential for bypassing IP-based access restrictions.
How do I fix CVE-2022-2362?
To fix CVE-2022-2362, update the Download Manager WordPress plugin to version 3.2.50 or later.
What types of attacks can exploit CVE-2022-2362?
CVE-2022-2362 can be exploited to bypass download restrictions based on IP addresses, potentially allowing unauthorized access to downloads.
Which versions of the Download Manager plugin are affected by CVE-2022-2362?
Versions of the Download Manager WordPress plugin prior to 3.2.50 are affected by CVE-2022-2362.
Is CVE-2022-2362 exploitable by regular users?
Yes, regular users with knowledge of HTTP headers can potentially exploit CVE-2022-2362 to bypass restrictions.