The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).
We have discovered 11,293 live websites that are affected by CVE-2023-6785.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 11,293 live websites (27.66% of WordPress Download Manager install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 122 versions ( 42.96% of all versions) |
![]() | 2,609 websites |
![]() | 1,683 websites |
![]() | 1,467 websites |
![]() | 667 websites |
![]() | 501 websites |
![]() | 348 websites |
![]() | 320 websites |
![]() | 253 websites |
![]() | 225 websites |
![]() | 200 websites |
.com | 3,974 websites |
.org | 809 websites |
.de | 707 websites |
.it | 414 websites |
.net | 388 websites |
.jp | 371 websites |
.fr | 210 websites |
.ru | 203 websites |
.co.jp | 202 websites |
.es | 199 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.org | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
********.org | ![]() | **,*** | |
*******.hu | ![]() | **,*** | |
*****.***.br | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
*********.***.pl | ![]() | ***,*** | |
*******.**.ke | ![]() | ***,*** | |
*********.org | ![]() | ***,*** | |
******.com | ![]() | ***,*** |
FAQ