The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-42505 | The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 22 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-05-22T15:41:20.288Z
Reserved: 2022-09-01T00:00:00.000Z
Link: CVE-2022-3076
Updated: 2024-08-03T01:00:09.712Z
Status : Modified
Published: 2022-09-26T13:15:11.090
Modified: 2025-05-22T16:15:53.110
Link: CVE-2022-3076
No data.
OpenCVE Enrichment
No data.
EUVD