CVE · Medium

CVE-2023-6785 — Download Manager [download-manager] < 3.2.85

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6785 Download Manager [download-manager] < 3.2.85 Improper Access Control Medium 5.3 < 3.2.85 3.2.85 2024-02-28

CVE-2023-6785

The WordPress Download Manager plugin prior to version 3.2.85 contains an access control vulnerability that allows unauthenticated or low-privileged users to perform actions restricted to higher-privileged roles due to missing authorization checks and nonce validation. The flaw was identified by wesley (wcraft) and stems from insufficient verification mechanisms in a plugin function. Users should upgrade to version 3.2.85 or later to resolve this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.