Download Manager <= 3.3.06 - Unauthenticated Information Disclosure via Unprotected Directory
2025-01-17 00:00
Dmitrii IgnatyevStrategic Overview
StatusPatched in 3.3.07
Affected PluginDownload Manager
Affected Version
<= 3.3.06CVSS5.3Medium
CVE
CVE-2024-13126Vulnerability Overview
The Download Manager plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 3.3.06. This is due to plugin not providing any access restrictions to the direct in which download files are uploaded. This makes it possible for unauthenticated attackers to access downloads that should be password protected by downloading them straight from the directory.
Technical Analysis
REMEDIATION: Update to version 3.3.07, or a newer patched version --- IDENTIFIER: CWE-552 (Files or Directories Accessible to External Parties) The product makes files or directories accessible to unauthorized actors, even though they should not be.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C