Download Manager < 3.3.07 - Unauthenticated Data Exposure
28Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 4.6epss 0.5%
exploitation probability
0.5%top 62% of all CVEs
observed exploitation
nono source reports it
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
Affected products
Unknown · Download Manager