PT-2025-11379 · WordPress · Download Manager

Dmitry Ignatyev

·

Published

2025-03-16

·

Updated

2025-04-05

·

CVE-2024-13126

CVSS v3.1

4.6

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Download Manager WordPress plugin versions prior to 3.3.07
Description The issue allows unauthorized access to files due to the plugin not preventing directory listing on web servers that don't use htaccess. This enables unauthorized access of files.
Recommendations For versions prior to 3.3.07, update to version 3.3.07 or later to resolve the issue. As a temporary workaround, consider configuring the web server to use htaccess to prevent directory listing until the plugin is updated.

Exploit

Fix

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2024-13126

Affected Products

Download Manager