First published: Tue May 02 2023(Updated: )
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Download Manager | >=6.0.0<6.3.0 | |
>=6.0.0<6.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1809 is a vulnerability in the Download Manager WordPress plugin before version 6.3.0 that allows attackers to download password-protected package files without a password.
CVE-2023-1809 has a severity rating of 7.5 (high).
The Download Manager WordPress plugin versions 6.0.0 to 6.3.0 (inclusive) are affected by CVE-2023-1809.
To fix CVE-2023-1809, update your Download Manager WordPress plugin to version 6.3.0 or later.
More information about CVE-2023-1809 can be found at this reference link: https://wpscan.com/vulnerability/57f0a078-fbeb-4b05-8892-e6d99edb82c1