Download Manager <= 3.2.49 - IP Blocking Bypass

2022-08-01 00:00
Raad Haddad

Strategic Overview

Status
Patched in 3.2.50
Affected PluginDownload Manager
Affected Version<= 3.2.49
CVSS5.3Medium
CVECVE-2022-2362
View all Download Manager vulnerabilities

Vulnerability Overview

The Download Manager plugin for WordPress is vulnerable to IP Blocking Bypass in versions up to, and including, 3.2.49 due to the way the visitor's IP address is determined. This allows an unauthenticated attacker to spoof their IP address to obtain access to files that are protected by this functionality.

Technical Analysis

REMEDIATION: Update to version 3.2.50, or a newer patched version --- IDENTIFIER: CWE-290 (Authentication Bypass by Spoofing) This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C