5.3
CVSSv3

CVE-2024-11768

CVSSv4: NA | CVSSv3: 5.3 | CVSSv2: NA | VMScore: 630 | EPSS: 0.00049 | KEV: Not Included
Published: 19/12/2024 Updated: 19/12/2024

Vulnerability Summary

Unauthorized Download Exploit in WordPress Download Manager Plugin

The WordPress Download Manager plugin has a vulnerability that lets people download password-protected files without permission. This happens because the checkFilePassword function does not properly validate passwords. All versions up to and including 3.3.03 are affected. Unauthenticated attackers can exploit this issue to get access to files.

Vulnerable Product Search on Vulmon Subscribe to Product

codename065 download manager