CVE Database /
CVE-2023-1524
CVE · Medium
CVE-2023-1524 — Download Manager [download-manager] < 3.2.71
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-1524
|
Download Manager [download-manager] < 3.2.71 |
Improper Access Control |
Medium
6.5
|
< 3.2.71
|
3.2.71 |
2023-05-08 |
—
|
CVE-2023-1524
The Download Manager plugin for WordPress through version 3.2.7.0 contains an information disclosure vulnerability stemming from inadequate password validation on protected files. An authenticated attacker with access to the downloads area can exploit this by creating a password-protected post that reveals a master key, which can then be combined with the original password to gain unauthorized access to all other password-protected posts.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings