CVE-2023-1524: w3eden Download Manager

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.

Affected products

  • w3eden Download Manager: before 3.2.71 (fixed in 3.2.71)

Published 2023-05-30. Last modified 2026-06-17.