← back
CVE-2024-13126medium

Download Manager < 3.3.07 - Unauthenticated Data Exposure

28Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 4.6epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L