Description
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58997 | The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published). |
References
History
Wed, 08 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Download Manager <= 3.2.84 - Missing Authorization | |
| Weaknesses | CWE-284 |
Fri, 21 Mar 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
W3eden
W3eden download Manager |
|
| Weaknesses | NVD-CWE-noinfo | CWE-862 |
| CPEs | cpe:2.3:a:w3eden:download_manager:*:*:*:*:free:wordpress:*:* | |
| Vendors & Products |
Wpdownloadmanager
Wpdownloadmanager download Manager |
W3eden
W3eden download Manager |
Wed, 12 Mar 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpdownloadmanager
Wpdownloadmanager download Manager |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:wpdownloadmanager:download_manager:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpdownloadmanager
Wpdownloadmanager download Manager |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:02:28.738Z
Reserved: 2023-12-13T15:52:15.178Z
Link: CVE-2023-6785
Updated: 2024-08-02T08:42:07.513Z
Status : Modified
Published: 2024-03-13T16:15:08.407
Modified: 2026-04-08T18:18:41.750
Link: CVE-2023-6785
No data.
OpenCVE Enrichment
No data.
EUVD