cleantalk
Vulnerabilities and Security Researches

Download Manager, bf80a7f6a2d48f38eeb6ada67189ba397eff748a

Application

Download Manager

Published on
Apr 16, 2021
Research Description
Download Manager [download-manager] < 3.1.17 Download Manager <= 3.1.17 - Missing Authorization The WordPress Download Manager plugin for WordPress is vulnerable to unauthorized download duplication in versions up to, and including, 3.1.17. This is due to missing authorization and nonce validation on the duplicate() function. This makes it possible for unauthenticated attackers to duplicate any of a vulnerable sites downloads.
Affected versions
max 3.1.17.
Status
vulnerable