Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary

2024-06-12 00:00
m1tz

Strategic Overview

Status
Patched in 3.2.90
Affected PluginDownload Manager
Affected Version<= 3.2.89
CVSS7.5High
CVECVE-2024-2098
View all Download Manager vulnerabilities

Vulnerability Overview

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.

Technical Analysis

REMEDIATION: Update to version 3.2.90, or a newer patched version --- IDENTIFIER: CWE-289 (Authentication Bypass by Alternate Name) The product performs authentication based on the name of a resource being accessed, or the name of the actor performing the access, but it does not properly check all possible names for that resource or actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C