cleantalk
Vulnerabilities and Security Researches

Download Manager, CVE-2023-6785

CVE, Research URL

CVE-2023-6785

Application

Download Manager

Published on
Mar 13, 2024
Research Description
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).
Affected versions
Min -, max 3.2.85.
Status
vulnerable