W3 Eden Download Manager
cpe:2.3:a:w3eden:download_manager:*:*:*:*:wordpress:*:*
- <= 3.3.30
A vulnerability exists in the Download Manager plugin for WordPress, in all versions through 3.3.30. The issue arises from a hardcoded Cron key that allows unauthorized access. This key is used in the 'deleteExpired()' and 'clearTempDataCPCron()' functions, enabling unauthenticated attackers to trigger these Cron jobs. As a result, expired posts can be deleted and cache cleared.
Exploitation of this vulnerability allows for unauthorized triggering of Cron jobs, leading to the deletion of expired posts and clearing of cache.
Users can update to version 3.3.31 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.