Unauthorized Download Exploit in WordPress Download Manager Plugin
The WordPress Download Manager plugin has a vulnerability that lets people download password-protected files without permission. This happens because the checkFilePassword function does not properly validate passwords. All versions up to and including 3.3.03 are affected. Unauthenticated attackers can exploit this issue to get access to files.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
codename065 download manager |