cleantalk
Vulnerabilities and Security Researches

Download Manager, CVE-2024-11768

CVE, Research URL

CVE-2024-11768

Application

Download Manager

Published on
Dec 19, 2024
Research Description
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
Affected versions
Min -, max 3.3.04.
Status
vulnerable