CVE-2023-6785

MEDIUM

Download Manager <= 3.2.84 - Unauthenticated Arbitrary File Download

Title source: llm
STIX 2.1

Description

The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).

Scores

CVSS v3 5.3
EPSS 0.0055
EPSS Percentile 41.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-862
Status published
Products (2)
codename065/Download Manager < 3.2.84
w3eden/download_manager < 3.2.85
Published Mar 13, 2024
Tracked Since Feb 18, 2026