Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33968 | The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 21 Mar 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
W3eden
W3eden download Manager |
|
| CPEs | cpe:2.3:a:w3eden:download_manager:*:*:*:*:free:wordpress:*:* | |
| Vendors & Products |
Wpdownloadmanager
Wpdownloadmanager download Manager |
W3eden
W3eden download Manager |
Wed, 29 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpdownloadmanager
Wpdownloadmanager download Manager |
|
| CPEs | cpe:2.3:a:wpdownloadmanager:download_manager:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpdownloadmanager
Wpdownloadmanager download Manager |
Thu, 19 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Dec 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. | |
| Title | Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-12-19T16:38:30.488Z
Reserved: 2024-11-26T12:37:35.772Z
Link: CVE-2024-11740
Updated: 2024-12-19T16:34:26.854Z
Status : Analyzed
Published: 2024-12-19T06:15:21.243
Modified: 2025-03-21T19:18:50.900
Link: CVE-2024-11740
No data.
OpenCVE Enrichment
No data.
EUVD