CVE-2024-8031

MEDIUM

Secure Downloads WP <1.2.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php.

Scores

CVSS v3 6.5
EPSS 0.0127
EPSS Percentile 79.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-552
Status published
Products (1)
wpbookingcalendar/secure_downloads < 1.2.3
Published May 15, 2025
Tracked Since Feb 18, 2026