The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
References
Configurations
History
No history.
Information
Published : 2024-12-19 06:15
Updated : 2025-03-21 19:18
NVD link : CVE-2024-11768
Mitre link : CVE-2024-11768
CVE.ORG link : CVE-2024-11768
JSON object : View
Products Affected
w3eden
- download_manager
CWE
