CVE-2024-11768: Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11768?
CVE-2024-11768 is a critical vulnerability allowing unauthorized download of password-protected content.
How do I fix CVE-2024-11768?
To fix CVE-2024-11768, update the Download Manager plugin for WordPress to version 3.3.04 or later.
Which versions are affected by CVE-2024-11768?
CVE-2024-11768 affects all versions of the Download Manager plugin up to and including version 3.3.03.
What types of attackers can exploit CVE-2024-11768?
CVE-2024-11768 can be exploited by unauthenticated attackers seeking unauthorized access to protected content.
What specific function is responsible for the vulnerability in CVE-2024-11768?
The vulnerability in CVE-2024-11768 is due to improper password validation in the checkFilePassword function.