The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
We have discovered 11,159 live websites that are affected by CVE-2024-11740.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 11,159 live websites (33% of Download Manager install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 201 versions ( 81% of all versions) |
| 1,972 websites | |
| 1,406 websites | |
| 1,132 websites | |
| 1,090 websites | |
| 532 websites | |
| 426 websites | |
| 376 websites | |
| 281 websites | |
| 232 websites | |
| 223 websites |
| .com | 3,684 websites |
| .org | 863 websites |
| .it | 739 websites |
| .de | 653 websites |
| .net | 356 websites |
| .jp | 334 websites |
| .ru | 225 websites |
| .fr | 218 websites |
| .eu | 201 websites |
| .co.jp | 196 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.pl | *,*** | ||
| ****.pt | **,*** | ||
| *****.org | **,*** | ||
| **********.com | **,*** | ||
| ********.org | **,*** | ||
| *****.***.br | **,*** | ||
| *********.com | **,*** | ||
| ***********************.org | **,*** | ||
| *********.org | ***,*** | ||
| *************.com | ***,*** |
FAQ