CVE Database · CVE-2024-13126
CVSS v3.1
4.6
EPSS
0.46%
Published
Mar 16, 2025
Modified
Apr 9, 2025
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:LWeaknesses (CWE)
Affected Products (1)
References (1)