The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
W3eden
W3eden download Manager |
|
CPEs | cpe:2.3:a:w3eden:download_manager:*:*:*:*:free:wordpress:*:* | |
Vendors & Products |
Wpdownloadmanager
Wpdownloadmanager download Manager |
W3eden
W3eden download Manager |
Wed, 29 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpdownloadmanager
Wpdownloadmanager download Manager |
|
CPEs | cpe:2.3:a:wpdownloadmanager:download_manager:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpdownloadmanager
Wpdownloadmanager download Manager |
Thu, 19 Dec 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 19 Dec 2024 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. | |
Title | Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution | |
Weaknesses | CWE-94 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-12-19T05:24:55.981Z
Updated: 2024-12-19T16:38:30.488Z
Reserved: 2024-11-26T12:37:35.772Z
Link: CVE-2024-11740

Updated: 2024-12-19T16:34:26.854Z

Status : Analyzed
Published: 2024-12-19T06:15:21.243
Modified: 2025-03-21T19:18:50.900
Link: CVE-2024-11740

No data.