CVE-2024-13126
The Download Manager plugin for WordPress through version 3.3.06 fails to properly restrict access to the directory containing uploaded download files, allowing unauthenticated users to retrieve files that are intended to be password-protected. An attacker can bypass the plugin's access controls by directly accessing files stored in the upload directory rather than using the proper download mechanism. This vulnerability affects all versions up to and including 3.3.06 and was fixed in version 3.3.07.
Based on public CVE data (MITRE/NVD).