CVE Database /
CVE-2024-2098
CVE · High
CVE-2024-2098 — Download Manager [download-manager] < 3.2.90
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-2098
|
Download Manager [download-manager] < 3.2.90 |
Authentication Bypass by Alternate Name |
High
7.5
|
< 3.2.90
|
3.2.90 |
2024-06-12 |
—
|
CVE-2024-2098
The Download Manager plugin for WordPress through version 3.2.89 contains an authorization flaw in the 'protectMediaLibrary' function that allows unauthenticated users to bypass password protection and download restricted files. This vulnerability exposes sensitive protected content to unauthorized access without requiring valid credentials.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings