CVE Database /
CVE-2021-34639
CVE · High
CVE-2021-34639 — Download Manager [download-manager] < 3.1.25
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-34639
|
Download Manager [download-manager] < 3.1.25 |
Unrestricted Upload of File with Dangerous Type |
High
8.8
|
< 3.1.25
|
3.1.25 |
2021-07-29 |
—
|
CVE-2021-34639
The Download Manager plugin before version 3.1.25 contains a flaw that permits users with Author-level permissions or higher to upload files using double extensions such as "payload.php.png", potentially resulting in code execution on certain server configurations. Although an .htaccess file in the upload directory provides protection against this issue in typical setups, the vulnerability could be exploited in environments where such protections are not in place.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings