CVE-2022-36288: WordPress Download Manager plugin <= 3.2.48 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
Published Aug 23, 2022
·Updated
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
Affected Software
2 affected components
Wpdownloadmanager Wordpress Download Manager Wordpress<=3.2.48
W3eden Download Manager Wordpress<=3.2.48
Remediation
Information
Update to 3.2.49 or higher version.
Event History
Aug 23, 2022
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-36288?
CVE-2022-36288 is classified as a high severity vulnerability due to its potential for misuse in cross-site request forgery attacks.
2
How do I fix CVE-2022-36288?
To fix CVE-2022-36288, update the W3 Eden Download Manager plugin to version 3.2.49 or later.
3
What types of attacks does CVE-2022-36288 enable?
CVE-2022-36288 enables multiple Cross-Site Request Forgery (CSRF) attacks that could lead to unauthorized actions on behalf of authenticated users.
4
Which versions of the W3 Eden Download Manager plugin are affected by CVE-2022-36288?
CVE-2022-36288 affects all versions of the W3 Eden Download Manager plugin up to and including 3.2.48.
5
Is there a workaround for CVE-2022-36288 if I cannot update immediately?
While the best practice is to update, a temporary workaround involves implementing CSRF tokens in the plugin settings where possible.