HIGH🇵🇱 Wersja polska

CVE-2024-2098

CVSS 7.5v3.1pub. 2024-06-13upd. 2026-04-08

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • W3eden Download Manager

    APP
    W3Eden
    < 3.2.90
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-11740HIGH7.3same product

The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions u...

CVE-2023-6421HIGH7.5same product

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upo...

CVE-2023-1809HIGH7.5same product

The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a passwor...

CVE-2022-2431HIGH8.1same product

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and incl...

CVE-2022-2436HIGH8.8same product

The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[pa...