CVE-2021-34639


WordPress Download Manager <= 3.1.24 Authenticated Arbitrary File Upload

Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions.



We have discovered 26 live websites that are affected by CVE-2021-34639.

Contact us to get more info




Affected Software

Product  WordPress Download Manager
Category Wordpress Plugins
Vulnerable Versions
  • from 3.1.24 through 3.1.24
Total Vulnerable Versions250
Vulnerable Domains26 live websites (<0.1% of WordPress Download Manager install base)


Common Weakness Enumeration


CWE-646 Reliance on File Name or Extension of Externally-Supplied File


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2021-34639 and the relative popularity of websites


Details

  • Published - Aug 6, 2021
  • Updated - Aug 6, 2021

Credits

  • Ramuel Gall, Wordfence





Countries

United States8 websites



Australia3 websites
France2 websites
Italy2 websites
Japan2 websites
Belgium1 websites
Brazil1 websites
Canada1 websites
Cyprus1 websites
Czech Republic1 websites

TLDs

.com10 websites
.org4 websites
.it2 websites
.be1 websites
.co.jp1 websites
.com.au1 websites
.cz1 websites
.de1 websites
.fr1 websites
.jp1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2021-34639 through included software libraries and plugins.



References


Websites affected by CVE-2021-34639

Top websites that are affected by CVE-2021-34639. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.**********.com Singapore***,***
***.***********.***.au Australia*,***,***
***********.***.au Australia*,***,***
***********.**.jp Japan*,***,***
*********.com United States*,***,***
***.*********.com Canada*,***,***
***.***********.cz Czech Republic**,***,***
************.jp Japan**,***,***
******.***.ls Lesotho**,***,***
************.***********.***.au Australia**,***,***
See full domain list