CVE-2024-13126medium

CVE-2024-13126: medium-severity vulnerability in Download Manager

Download Manager < 3.3.07 - Unauthenticated Data Exposure

Published · Updated

28Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 4.6epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L