PoC Index

CVE-2022-3076

HIGH 7.2EPSS 1.2%

The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.

CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
1.18% chance of exploitation in the next 30 days, 65th percentile
Published
2022-09-26
Updated
2025-05-22

Proof-of-concept exploits (1)

References

Related