CVE-2023-1524
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2023-1524 is a vulnerability affecting the Download Manager plugin for WordPress before version 3.2.71. This issue permits unauthorized users to download password-protected files by exploiting the weak validation process for passwords. The plugin generates a master key that is exposed to the user upon validation, making it possible for attackers to gain access to any password-protected file on the server, as long as they know the password for just one of those files. This vulnerability poses a significant risk to WordPress websites and requires immediate patching to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.