VendorsWP-DownloadManager Projectwp-downloadmanager1.68.4
Vulnerabilities

WP-DownloadManager Project WP-DownloadManager 1.68.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2020-24141
Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local network hosts and execute command on services
Published 2021-07-07 · Modified
5.3EPSS 0.009