CVE-2022-36345: WordPress Download Plugin Plugin <= 2.0.4 is vulnerable to Cross Site Request Forgery (CSRF)
Published May 28, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Plugin <= 2.0.4 versions.
Affected Software
1 affected component
Metagauss Download Plugin Wordpress<2.0.5
Remediation
Information
Update to 2.0.5 or a higher version.
Event History
May 28, 2023
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-36345?
CVE-2022-36345 is a Cross-Site Request Forgery (CSRF) vulnerability in the Metagauss Download Plugin version 2.0.4 and earlier for WordPress.
2
How severe is CVE-2022-36345?
CVE-2022-36345 has a severity score of 8.8, which is considered high.
3
How does CVE-2022-36345 affect Metagauss Download Plugin?
CVE-2022-36345 affects Metagauss Download Plugin versions 2.0.4 and earlier, allowing for Cross-Site Request Forgery attacks.
4
What is the Common Weakness Enumeration (CWE) for CVE-2022-36345?
CVE-2022-36345 is associated with CWE-352, which is Cross-Site Request Forgery (CSRF).
5
How can I fix CVE-2022-36345?
To fix CVE-2022-36345, update Metagauss Download Plugin to version 2.0.5 or later.