CVE-2024-13126

CVSS 3.1 Score 4.6 of 10 (medium)

Details

Published Mar 16, 2025
Updated: Mar 17, 2025

Summary

CVE-2024-13126 is a vulnerability affecting the Download Manager WordPress plugin before version 3.3.07. This issue permits unauthorized access to files when the plugin is installed on web servers that do not utilize the .htaccess file to prevent directory listing. Consequently, attackers can potentially view sensitive information or download restricted files, posing a significant security risk. WordPress users running older versions of the Download Manager plugin are advised to update immediately to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share