First published: Tue Apr 18 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Download Manager | <3.2.60 |
Update to 3.2.60 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-45836 is high.
The affected software for CVE-2022-45836 is the W3 Eden, Inc. Download Manager plugin version 3.2.59 and below.
To fix CVE-2022-45836, update the W3 Eden, Inc. Download Manager plugin to version 3.2.60 or higher.
The Common Weakness Enumeration (CWE) for CVE-2022-45836 is CWE-79 (Cross-site Scripting).
You can find more information about CVE-2022-45836 at the following link: [https://patchstack.com/database/vulnerability/download-manager/wordpress-download-manager-plugin-3-2-59-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve](https://patchstack.com/database/vulnerability/download-manager/wordpress-download-manager-plugin-3-2-59-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve).