The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
We have discovered 19,198 live websites that are affected by CVE-2024-11740.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 19,198 live websites (47.01% of WordPress Download Manager install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 140 versions ( 49.30% of all versions) |
![]() | 5,022 websites |
![]() | 2,591 websites |
![]() | 2,542 websites |
![]() | 1,135 websites |
![]() | 772 websites |
![]() | 582 websites |
![]() | 529 websites |
![]() | 402 websites |
![]() | 352 websites |
![]() | 302 websites |
.com | 6,786 websites |
.org | 1,500 websites |
.de | 1,331 websites |
.it | 652 websites |
.net | 648 websites |
.jp | 555 websites |
.fr | 373 websites |
.co.uk | 351 websites |
.nl | 342 websites |
.pl | 303 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****.pl | ![]() | *,*** | |
****.pt | ![]() | **,*** | |
*****.org | ![]() | **,*** | |
**.******.com | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
********.org | ![]() | **,*** | |
*******.hu | ![]() | **,*** | |
*****.***.br | ![]() | **,*** | |
*********.com | ![]() | **,*** |
FAQ