CVE-2024-11768

The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:w3eden:download_manager:*:*:*:*:free:wordpress:*:*

History

21 Mar 2025, 19:18

Type Values Removed Values Added
First Time W3eden download Manager
W3eden
CPE cpe:2.3:a:wpdownloadmanager:download_manager:*:*:*:*:*:wordpress:*:* cpe:2.3:a:w3eden:download_manager:*:*:*:*:free:wordpress:*:*

29 Jan 2025, 20:54

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://plugins.trac.wordpress.org/browser/download-manager/trunk/src/__/Apply.php#L376 - () https://plugins.trac.wordpress.org/browser/download-manager/trunk/src/__/Apply.php#L376 - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/feb915f4-66d6-4f46-949c-5354e414319b?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/feb915f4-66d6-4f46-949c-5354e414319b?source=cve - Third Party Advisory
First Time Wpdownloadmanager
Wpdownloadmanager download Manager
CPE cpe:2.3:a:wpdownloadmanager:download_manager:*:*:*:*:*:wordpress:*:*
Summary
  • (es) El complemento Download Manager para WordPress es vulnerable a la descarga no autorizada de contenido protegido con contraseña debido a una validación incorrecta de la contraseña en la función checkFilePassword en todas las versiones hasta la 3.3.03 incluida. Esto permite que atacantes no autenticados descarguen archivos protegidos con contraseña.

19 Dec 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-19 06:15

Updated : 2025-03-21 19:18


NVD link : CVE-2024-11768

Mitre link : CVE-2024-11768

CVE.ORG link : CVE-2024-11768


JSON object : View

Products Affected

w3eden

  • download_manager
CWE
CWE-285

Improper Authorization

NVD-CWE-noinfo