CVE-2020-24141: Wp-Downloadmanager Project Wp-Downloadmanager
Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.
Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local network hosts and execute command on services
Affected products
- Wp-Downloadmanager Project Wp-Downloadmanager: version 1.68.4 only
Published 2021-07-07. Last modified 2026-06-17.