CVE-2024-11768

The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:w3eden:download_manager:*:*:*:*:free:wordpress:*:*

History

21 Mar 2025, 19:18

Type Values Removed Values Added
CPE cpe:2.3:a:wpdownloadmanager:download_manager:*:*:*:*:*:wordpress:*:* cpe:2.3:a:w3eden:download_manager:*:*:*:*:free:wordpress:*:*
First Time W3eden download Manager
W3eden

29 Jan 2025, 20:54

Type Values Removed Values Added
CPE cpe:2.3:a:wpdownloadmanager:download_manager:*:*:*:*:*:wordpress:*:*
First Time Wpdownloadmanager
Wpdownloadmanager download Manager
References () https://plugins.trac.wordpress.org/browser/download-manager/trunk/src/__/Apply.php#L376 - () https://plugins.trac.wordpress.org/browser/download-manager/trunk/src/__/Apply.php#L376 - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/feb915f4-66d6-4f46-949c-5354e414319b?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/feb915f4-66d6-4f46-949c-5354e414319b?source=cve - Third Party Advisory
Summary
  • (es) El complemento Download Manager para WordPress es vulnerable a la descarga no autorizada de contenido protegido con contraseña debido a una validación incorrecta de la contraseña en la función checkFilePassword en todas las versiones hasta la 3.3.03 incluida. Esto permite que atacantes no autenticados descarguen archivos protegidos con contraseña.
CWE NVD-CWE-noinfo

19 Dec 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-19 06:15

Updated : 2025-03-21 19:18


NVD link : CVE-2024-11768

Mitre link : CVE-2024-11768

CVE.ORG link : CVE-2024-11768


JSON object : View

Products Affected

w3eden

  • download_manager
CWE
CWE-285

Improper Authorization

NVD-CWE-noinfo