The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/c2c69a44-4ecc-41d1-a10c-cfe9c875b803/ | third party advisory vdb entry exploit technical description |