First published: Thu Dec 19 2024(Updated: )
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
Credit: security@wordfence.com
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.