First published: Thu Dec 19 2024(Updated: )
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Download manager Download manager | <=3.3.03 | |
WP Download Manager | <3.3.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-11768 is a critical vulnerability allowing unauthorized download of password-protected content.
To fix CVE-2024-11768, update the Download Manager plugin for WordPress to version 3.3.04 or later.
CVE-2024-11768 affects all versions of the Download Manager plugin up to and including version 3.3.03.
CVE-2024-11768 can be exploited by unauthenticated attackers seeking unauthorized access to protected content.
The vulnerability in CVE-2024-11768 is due to improper password validation in the checkFilePassword function.