CVE-2022-34658: WordPress Download Manager plugin <= 3.2.48 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities
Published Aug 23, 2022
·Updated
Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
Affected Software
2 affected components
Wpdownloadmanager Wordpress Download Manager Wordpress<=3.2.48
W3eden Download Manager Wordpress<=3.2.48
Remediation
Information
Update to 3.2.49 or higher version.
Event History
Aug 23, 2022
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-34658?
The severity of CVE-2022-34658 is classified as high due to multiple persistent cross-site scripting vulnerabilities.
2
How do I fix CVE-2022-34658?
To fix CVE-2022-34658, update the W3 Eden Download Manager plugin to version 3.2.49 or later.
3
Who is affected by CVE-2022-34658?
Anyone using the W3 Eden Download Manager plugin version 3.2.48 or lower on their WordPress site is affected by CVE-2022-34658.
4
What consequences can result from CVE-2022-34658?
CVE-2022-34658 can allow attackers to execute arbitrary JavaScript code, potentially leading to data theft or site compromise.
5
Is CVE-2022-34658 a common vulnerability?
Yes, persistent cross-site scripting vulnerabilities like CVE-2022-34658 are common in web applications and pose significant risks.