CVE · High

CVE-2021-34639 — Download Manager [download-manager] < 3.1.25

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-34639 Download Manager [download-manager] < 3.1.25 Unrestricted Upload of File with Dangerous Type High 8.8 < 3.1.25 3.1.25 2021-07-29

CVE-2021-34639

The Download Manager plugin before version 3.1.25 contains a flaw that permits users with Author-level permissions or higher to upload files using double extensions such as "payload.php.png", potentially resulting in code execution on certain server configurations. Although an .htaccess file in the upload directory provides protection against this issue in typical setups, the vulnerability could be exploited in environments where such protections are not in place.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.