CVE-2024-13126
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Published Mar 16, 2025
Updated: Mar 17, 2025
Summary
CVE-2024-13126 is a vulnerability affecting the Download Manager WordPress plugin before version 3.3.07. This issue permits unauthorized access to files when the plugin is installed on web servers that do not utilize the .htaccess file to prevent directory listing. Consequently, attackers can potentially view sensitive information or download restricted files, posing a significant security risk. WordPress users running older versions of the Download Manager plugin are advised to update immediately to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.