CVE · High

CVE-2024-32131 — Download Manager [download-manager] < 3.2.83

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-32131 Download Manager [download-manager] < 3.2.83 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 3.2.83 3.2.83 2024-04-12

CVE-2024-32131

The Download Manager WordPress plugin versions before 3.2.83 contain a bypass vulnerability that allows attackers to circumvent code restrictions. The vendor has not responded since November 15, 2023, and no patch has been released to address the issue. The security researcher Liu Shaohong discovered and reported this flaw, which remains unresolved and has been escalated to the WordPress plugins review team.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.