CVE-2024-13126

MEDIUM NUCLEI

WordPress Plugin <3.3.07 - Path Traversal

Title source: llm

Description

The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.

Nuclei Templates (1)

WordPress Download Manager < 3.3.07 - Unauthenticated Data Exposure
MEDIUMVERIFIEDby ritikchaddha
Shodan: html:"wp-content/plugins/download-manager/"
FOFA: body="wp-content/plugins/download-manager/"

Scores

CVSS v3 4.6
EPSS 0.0152
EPSS Percentile 81.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

Details

CWE
CWE-552
Status published
Products (1)
w3eden/download_manager < 3.3.07
Published Mar 16, 2025
Tracked Since Feb 18, 2026