CVE-2021-25087: vulnerability in Download Manager
Wordpress Download Manager < 3.2.25 - Sensitive Information Disclosure
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.5%
exploitation probability
1.5%top 26% of all CVEs
observed exploitation
nono source reports it
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).
Affected products
Unknown · Download ManagerRelated CVEs — Download Manager
In the same product, most dangerous first.
CVE-2023-6421HIGHDownload Manager < 3.2.83 - Unauthenticated Protected File Download Password LeakEPSS 2.4%CVE-2022-2926MEDIUMDownload Manager < 3.2.55 - Admin+ Arbitrary File/Folder Access via Path TraversalEPSS 1.7%CVE-2022-0828—Download Manager < 3.2.39 - Unauthenticated brute force of files master keyEPSS 1.5%CVE-2021-25069—WordPress Download Manager < 3.2.34 - Authenticated SQL Injection to Reflected XSSEPSS 1.5%CVE-2022-2168—Download Manager < 3.2.44 - Reflected Cross-Site ScriptingEPSS 1.4%CVE-2022-2362—Download Manager < 3.2.50 - Bypass IP Address Blocking RestrictionEPSS 1.2%