4.6
CVE-2024-13126
- EPSS 0.61%
- Veröffentlicht 16.03.2025 06:15:11
- Zuletzt bearbeitet 09.04.2025 13:06:59
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Download Manager <= 3.3.06 - Unauthenticated Information Disclosure via Unprotected Directory
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
Mögliche Gegenmaßnahme
Download Manager: Update to version 3.3.07, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Download Manager
Version
* - 3.3.06
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
W3eden ≫ Download Manager SwEditionfree SwPlatformwordpress Version < 3.3.07
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.61% | 0.688 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.6 | 1.2 | 3.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.