Unrated severityNVD Advisory· Published Aug 22, 2022· Updated Aug 3, 2024
Download Manager < 3.2.50 - Bypass IP Address Blocking Restriction
CVE-2022-2362
Description
The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions.
Affected products
1- Range: 3.2.50
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/d94b721e-9ce2-45e5-a673-2a57b0137653mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.