Skip to content

Known CVE

WordPress Download Manager < 3.3.07 - Unauthenticated Data Exposure

The WordPress Download Manager plugin before version 3.3.07 does not prevent directory listing on web servers that don't use htaccess, allowing unauthorized access to files stored in the download-manager-files directory.

CVE-2024-13126

Medium2024CVSS 5.3CWE-552

cve2024 · wp · wordpress · wp-plugin · directory-listing · download-manager · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website