The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/57f0a078-fbeb-4b05-8892-e6d99edb82c1 | third party advisory vdb entry exploit technical description |