CVE Database
/

CVE-2021-25087

Back to search

CVE-2021-25087

Published: Mar 7, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).

VendorProductVersions

Unknown

Download Manager

affected
3.2.35 - < 3.2.35

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now