Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary
2024-06-12 00:00
m1tzStrategic Overview
StatusPatched in 3.2.90
Affected PluginDownload Manager
Affected Version
<= 3.2.89CVSS7.5High
CVE
CVE-2024-2098Vulnerability Overview
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.
Technical Analysis
REMEDIATION: Update to version 3.2.90, or a newer patched version --- IDENTIFIER: CWE-289 (Authentication Bypass by Alternate Name) The product performs authentication based on the name of a resource being accessed, or the name of the actor performing the access, but it does not properly check all possible names for that resource or actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C