CVE Database /
CVE-2024-32131
CVE · High
CVE-2024-32131 — Download Manager [download-manager] < 3.2.83
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-32131
|
Download Manager [download-manager] < 3.2.83 |
Exposure of Sensitive Information to an Unauthorized Actor |
High
7.5
|
< 3.2.83
|
3.2.83 |
2024-04-12 |
—
|
CVE-2024-32131
The Download Manager WordPress plugin versions before 3.2.83 contain a bypass vulnerability that allows attackers to circumvent code restrictions. The vendor has not responded since November 15, 2023, and no patch has been released to address the issue. The security researcher Liu Shaohong discovered and reported this flaw, which remains unresolved and has been escalated to the WordPress plugins review team.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings