AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-3076

HIGH · CVSS 7.2 EPSS 1.13%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-09-26 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.2. It affects WordPress.

CVE
CVE-2022-3076
Severity
HIGH
CVSS
7.2
EPSS
1.13%
WordPress

Original NVD Description

The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.

Related CVEs

Other vulnerabilities affecting the same vendor(s)