Download Manager WordPress Plugin Unauthenticated Directory Listing Vulnerability

Vulnerability

A vulnerability exists in the Download Manager WordPress plugin in versions prior to 3.3.07, where the plugin fails to disable directory listing on web servers not using htaccess. This oversight allows unauthorized users to access files within the directory.

Impact

Exploitation of this vulnerability could lead to unauthorized access to files on the server.

Remediation

Users are advised to update the Download Manager WordPress plugin to version 3.3.07 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.