CVE · Medium

CVE-2024-13126 — Download Manager [download-manager] < 3.3.07

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13126 Download Manager [download-manager] < 3.3.07 Files or Directories Accessible to External Parties Medium 4.6 < 3.3.07 3.3.07 2025-01-17

CVE-2024-13126

The Download Manager plugin for WordPress through version 3.3.06 fails to properly restrict access to the directory containing uploaded download files, allowing unauthenticated users to retrieve files that are intended to be password-protected. An attacker can bypass the plugin's access controls by directly accessing files stored in the upload directory rather than using the proper download mechanism. This vulnerability affects all versions up to and including 3.3.06 and was fixed in version 3.3.07.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.