The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download password-protected files.
We have discovered 11,159 live websites that are affected by CVE-2024-11768.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 11,159 live websites (33% of Download Manager install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 201 versions ( 81% of all versions) |
| 1,972 websites | |
| 1,406 websites | |
| 1,132 websites | |
| 1,090 websites | |
| 532 websites | |
| 426 websites | |
| 376 websites | |
| 281 websites | |
| 232 websites | |
| 223 websites |
| .com | 3,684 websites |
| .org | 863 websites |
| .it | 739 websites |
| .de | 653 websites |
| .net | 356 websites |
| .jp | 334 websites |
| .ru | 225 websites |
| .fr | 218 websites |
| .eu | 201 websites |
| .co.jp | 196 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.pl | *,*** | ||
| ****.pt | **,*** | ||
| *****.org | **,*** | ||
| **********.com | **,*** | ||
| ********.org | **,*** | ||
| *****.***.br | **,*** | ||
| *********.com | **,*** | ||
| ***********************.org | **,*** | ||
| *********.org | ***,*** | ||
| *************.com | ***,*** |
FAQ