ZeroHour

CVE-2023-6785

CVSS 3.1
5.3 medium
EPSS
<1%p44
Published
()
Modified
Description

The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).

Vendors
w3eden
Products
download manager
Ecosystems
WordPress
Weakness
CWE-284, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.