CVE-2023-6421

Download Manager < 3.2.83 - Unauthenticated Protected File Download Password Leak

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.


We have discovered 10,223 live websites that are affected by CVE-2023-6421.

Test my site




Affected Software

Product  WordPress Download Manager
Category Wordpress Plugins
Vulnerable Domains10,223 live websites (25.03% of WordPress Download Manager install base)
Vulnerable Versions
  • from 0 before 3.2.83
Vulnerable Versions Count120 versions ( 42.25% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Jan 1, 2024
  • Updated - Aug 2, 2024

Credits

  • Liu Shaohong (finder)
  • WPScan (coordinator)

CVE-2023-6421 usage by Country

United States2,359 websites



Japan1,542 websites
Germany1,291 websites
France600 websites
Italy447 websites
Spain324 websites
GB289 websites
Poland223 websites
Russia212 websites
Netherlands176 websites

CVE-2023-6421 usage by TLD

.com3,627 websites
.org733 websites
.de624 websites
.it369 websites
.net349 websites
.jp336 websites
.ru195 websites
.fr186 websites
.co.jp182 websites
.es181 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-6421

Top websites that are affected by CVE-2023-6421. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.org United States**,***
**********.com United States**,***
********.org United States**,***
*******.hu Hungary**,***
*****.***.br United States**,***
*********.com Japan**,***
*********.***.pl Poland***,***
*********.org United States***,***
******.com Japan***,***
***********.asia United States***,***
See full domain list

FAQ

CVE-2023-6421 is Incorrect Authorization in WordPress Download Manager
A total of 10,223 websites have been identified as vulnerable to CVE-2023-6421, discovered through global website indexing conducted by WebTechSurvey.
WordPress Download Manager is susceptible to CVE-2023-6421 vulnerability.
WordPress Download Manager versions before 3.2.83 are vulnerable to CVE-2023-6421.
Version 3.2.83 of WordPress Download Manager addresses the CVE-2023-6421 security vulnerability.