CVE-2023-6421
HIGH 7.5EPSS 2.4%
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS
- 2.44% chance of exploitation in the next 30 days, 83th percentile
- Nuclei
- medium · CWE-200
- Published
- 2024-01-01
- Updated
- 2025-06-18
Proof-of-concept exploits (2)
- https://wpscan.com/vulnerability/244c7c00-fc8d-4a73-bbe0-7865c621d410
- RandomRobbieBF/CVE-2023-64211★ · 2024-10-09