PT-2024-18821 · WordPress · Download Manager

M1Tz

+1

·

Published

2024-06-13

·

Updated

2025-03-11

·

CVE-2024-2098

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Download Manager plugin for WordPress versions up to, and including, 3.2.89
Description The issue arises from an improper authorization check on the protectMediaLibrary function, allowing unauthenticated attackers to access password-protected files. This enables unauthorized data access, specifically permitting attackers to download files that should be restricted.
Recommendations For versions up to, and including, 3.2.89, update to a version higher than 3.2.89 to resolve the issue. As a temporary workaround, consider disabling the protectMediaLibrary function until a patch is available.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-2098

Affected Products

Download Manager