First published: Tue Aug 23 2022(Updated: )
Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Download Manager | <=3.2.48 |
Update to 3.2.49 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-34658 is classified as high due to multiple persistent cross-site scripting vulnerabilities.
To fix CVE-2022-34658, update the W3 Eden Download Manager plugin to version 3.2.49 or later.
Anyone using the W3 Eden Download Manager plugin version 3.2.48 or lower on their WordPress site is affected by CVE-2022-34658.
CVE-2022-34658 can allow attackers to execute arbitrary JavaScript code, potentially leading to data theft or site compromise.
Yes, persistent cross-site scripting vulnerabilities like CVE-2022-34658 are common in web applications and pose significant risks.