CVE · Medium

CVE-2024-11768 — Download Manager [download-manager] < 3.3.04

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-11768 Download Manager [download-manager] < 3.3.04 Improper Authorization Medium 5.3 < 3.3.04 3.3.04 2024-12-18

CVE-2024-11768

The Download Manager plugin for WordPress contains a flaw in its checkFilePassword function that fails to properly validate passwords, affecting versions 3.3.03 and earlier. This vulnerability allows unauthenticated attackers to bypass password protection and gain access to download files that should be restricted. The improper validation mechanism creates a security gap that exposes password-protected content to unauthorized access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.