CVE-2024-11740

Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution

The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.


We have discovered 19,198 live websites that are affected by CVE-2024-11740.

Test my site




Affected Software

Product  WordPress Download Manager
Category Wordpress Plugins
Vulnerable Domains19,198 live websites (47.01% of WordPress Download Manager install base)
Vulnerable Versions
  • from 0 through 3.3.3
Vulnerable Versions Count140 versions ( 49.30% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Dec 19, 2024
  • Updated - Dec 19, 2024

Credits

  • Michael Mazzolini (finder)

CVE-2024-11740 usage by Country

United States5,022 websites



Germany2,591 websites
Japan2,542 websites
France1,135 websites
Italy772 websites
GB582 websites
Spain529 websites
Poland402 websites
Netherlands352 websites
Russia302 websites

CVE-2024-11740 usage by TLD

.com6,786 websites
.org1,500 websites
.de1,331 websites
.it652 websites
.net648 websites
.jp555 websites
.fr373 websites
.co.uk351 websites
.nl342 websites
.pl303 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-11740

Top websites that are affected by CVE-2024-11740. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.pl Poland*,***
****.pt Portugal**,***
*****.org United States**,***
**.******.com United States**,***
**********.com United States**,***
*********.com United States**,***
********.org United States**,***
*******.hu Hungary**,***
*****.***.br United States**,***
*********.com Japan**,***
See full domain list

FAQ

CVE-2024-11740 is Improper Control of Generation of Code ('Code Injection') in WordPress Download Manager
A total of 19,198 websites have been identified as vulnerable to CVE-2024-11740, discovered through global website indexing conducted by WebTechSurvey.
WordPress Download Manager is susceptible to CVE-2024-11740 vulnerability.
WordPress Download Manager versions before, and including, 3.3.3 are vulnerable to CVE-2024-11740.