Description
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
Published: 2024-12-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-33793 The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00046}

epss

{'score': 0.00049}


Fri, 21 Mar 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared W3eden
W3eden download Manager
CPEs cpe:2.3:a:wpdownloadmanager:download_manager:*:*:*:*:*:wordpress:*:* cpe:2.3:a:w3eden:download_manager:*:*:*:*:free:wordpress:*:*
Vendors & Products Wpdownloadmanager
Wpdownloadmanager download Manager
W3eden
W3eden download Manager

Wed, 29 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Wpdownloadmanager
Wpdownloadmanager download Manager
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:wpdownloadmanager:download_manager:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpdownloadmanager
Wpdownloadmanager download Manager

Thu, 19 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Dec 2024 05:45:00 +0000

Type Values Removed Values Added
Description The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
Title Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

W3eden Download Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:35:13.165Z

Reserved: 2024-11-26T15:16:24.789Z

Link: CVE-2024-11768

cve-icon Vulnrichment

Updated: 2024-12-19T16:34:24.277Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-19T06:15:23.007

Modified: 2025-03-21T19:18:21.113

Link: CVE-2024-11768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses