CVE · High

CVE-2024-11740 — Download Manager [download-manager] < 3.3.04

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-11740 Download Manager [download-manager] < 3.3.04 Improper Control of Generation of Code ('Code Injection') High 7.3 < 3.3.04 3.3.04 2024-12-18

CVE-2024-11740

The Download Manager plugin for WordPress through version 3.3.03 contains a vulnerability that permits unauthenticated attackers to execute arbitrary shortcodes. An action within the plugin fails to properly sanitize user input before passing it to do_shortcode, allowing malicious actors to invoke any registered shortcode without authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.