CVE-2023-1809: Download Manager Pro < 6.3.0 - Unauthenticated Sensitive Information Disclosure
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1809?
CVE-2023-1809 is a vulnerability in the Download Manager WordPress plugin before version 6.3.0 that allows attackers to download password-protected package files without a password.
How severe is CVE-2023-1809?
CVE-2023-1809 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2023-1809?
The Download Manager WordPress plugin versions 6.0.0 to 6.3.0 (inclusive) are affected by CVE-2023-1809.
How can I fix CVE-2023-1809?
To fix CVE-2023-1809, update your Download Manager WordPress plugin to version 6.3.0 or later.
Where can I find more information about CVE-2023-1809?
More information about CVE-2023-1809 can be found at this reference link: https://wpscan.com/vulnerability/57f0a078-fbeb-4b05-8892-e6d99edb82c1