CVE-2022-4476: Download Manager < 3.2.62 - Contributor+ Stored XSS
The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4476?
CVE-2022-4476 is considered a medium severity vulnerability that can lead to Stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2022-4476?
To fix CVE-2022-4476, update the Download Manager WordPress plugin to version 3.2.62 or later.
Who is affected by CVE-2022-4476?
CVE-2022-4476 affects users of the Download Manager WordPress plugin prior to version 3.2.62.
What types of attacks can CVE-2022-4476 lead to?
CVE-2022-4476 can allow users with low-level roles, like contributors, to perform Stored Cross-Site Scripting attacks.
What plugin is associated with CVE-2022-4476?
CVE-2022-4476 is associated with the Download Manager WordPress plugin.