7.3
CVSSv3

CVE-2024-11740

CVSSv4: NA | CVSSv3: 7.3 | CVSSv2: NA | VMScore: 830 | EPSS: 0.03879 | KEV: Not Included
Published: 19/12/2024 Updated: 19/12/2024

Vulnerability Summary

Arbitrary Shortcode Execution Vulnerability in WordPress Download Manager Plugin

The Download Manager plugin for WordPress has a vulnerability in all versions up to 3.3.03. This problem occurs because the software runs an action without checking a value properly before using do_shortcode. Because of this, attackers who are not authenticated can run arbitrary shortcodes.

Vulnerable Product Search on Vulmon Subscribe to Product

codename065 download manager