CVE-2022-34347: WordPress Download Manager plugin <= 3.2.48 - Cross-Site Request Forgery (CSRF) vulnerability
Published Aug 22, 2022
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
Affected Software
2 affected components
Wpdownloadmanager Wordpress Download Manager Wordpress<=3.2.48
W3eden Download Manager Wordpress<=3.2.48
Remediation
Information
Update to 3.2.49 or higher version.
Event History
Aug 22, 2022
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-34347?
CVE-2022-34347 is classified as a medium severity vulnerability.
2
How do I fix CVE-2022-34347?
To fix CVE-2022-34347, you should update the W3 Eden Download Manager plugin to version 3.2.49 or later.
3
Who is affected by CVE-2022-34347?
CVE-2022-34347 affects users of the W3 Eden Download Manager plugin version 3.2.48 and earlier.
4
What type of vulnerability is CVE-2022-34347?
CVE-2022-34347 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2022-34347 be exploited remotely?
Yes, CVE-2022-34347 can potentially be exploited remotely if an attacker tricks a user into performing actions without their consent.