CVE-2024-11740

Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution

The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.


We have discovered 11,159 live websites that are affected by CVE-2024-11740.

Run a Free Instant Scan




Affected Software

Product  Download Manager
Category Wordpress Plugins
Vulnerable Domains11,159 live websites (33% of Download Manager install base)
Vulnerable Versions
  • from 0 through 3.3.3
Vulnerable Versions Count201 versions ( 81% of all versions)


Common Weakness Enumeration

CWE-94 Improper Control of Generation of Code ('Code Injection')



Details

  • Published - Dec 19, 2024
  • Updated - Apr 8, 2026

Credits

  • Michael Mazzolini (finder)

Website Distribution by Country

Number of websites using CVE-2024-11740
United States1,972 websites



Japan1,406 websites
Germany1,132 websites
Italy1,090 websites
France532 websites
Spain426 websites
GB376 websites
Russia281 websites
Poland232 websites
Brazil223 websites

Website Distribution by TLD

Number of websites using CVE-2024-11740
.com3,684 websites
.org863 websites
.it739 websites
.de653 websites
.net356 websites
.jp334 websites
.ru225 websites
.fr218 websites
.eu201 websites
.co.jp196 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-11740

Top websites that are affected by CVE-2024-11740. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.pl Poland*,***
****.pt Portugal**,***
*****.org United States**,***
**********.com United States**,***
********.org United States**,***
*****.***.br Brazil**,***
*********.com Japan**,***
***********************.org United States**,***
*********.org United States***,***
*************.com United States***,***
See full domain list

FAQ

CVE-2024-11740 is Improper Control of Generation of Code ('Code Injection') in Download Manager
A total of 11,159 websites have been identified as vulnerable to CVE-2024-11740, based on global website indexing conducted by WebTechSurvey.
The Download Manager is affected by the CVE-2024-11740 vulnerability.
Download Manager versions up to and including 3.3.3 are vulnerable to CVE-2024-11740.