CVE-2024-8031: Secure Downloads < 1.2.3 - Admin+ Arbitrary File Download
The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8031?
CVE-2024-8031 is considered a high severity vulnerability due to its risk of unauthorized file downloads.
How do I fix CVE-2024-8031?
To mitigate CVE-2024-8031, update the Secure Downloads WordPress plugin to version 1.2.3 or later.
Who is affected by CVE-2024-8031?
CVE-2024-8031 affects users of the Secure Downloads WordPress plugin versions prior to 1.2.3.
What kind of files can be downloaded with CVE-2024-8031?
CVE-2024-8031 allows authenticated attackers with admin-level access to download arbitrary files, potentially exposing sensitive information.
Can unauthenticated users exploit CVE-2024-8031?
No, CVE-2024-8031 requires authenticated users with admin-level access to exploit the vulnerability.