The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
W3eden
W3eden download Manager |
|
CPEs | cpe:2.3:a:w3eden:download_manager:*:*:*:*:free:wordpress:*:* | |
Vendors & Products |
Wpdownloadmanager
Wpdownloadmanager download Manager |
W3eden
W3eden download Manager |
Tue, 11 Mar 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpdownloadmanager
Wpdownloadmanager download Manager |
|
Weaknesses | CWE-863 | |
CPEs | cpe:2.3:a:wpdownloadmanager:download_manager:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpdownloadmanager
Wpdownloadmanager download Manager |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T19:03:38.699Z
Reserved: 2024-03-01T15:59:07.828Z
Link: CVE-2024-2098

Updated: 2024-08-01T19:03:38.699Z

Status : Analyzed
Published: 2024-06-13T06:15:09.453
Modified: 2025-03-21T19:16:48.597
Link: CVE-2024-2098

No data.