CVE-2024-8031

MEDIUM

Secure Downloads WP <1.2.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/c6f54e6f-0a50-424f-ae3a-00b9880d9f13/

Scores

CVSS v3 6.5
EPSS 0.0042
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-552
Status published
Products (1)
wpbookingcalendar/secure_downloads < 1.2.3
Published May 15, 2025
Tracked Since Feb 18, 2026