CVE-2024-13126: w3eden Download Manager
Medium severity, CVSS 4.6. EPSS: 0.5% chance of exploitation in the next 30 days.
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.
Affected products
- w3eden Download Manager: before 3.3.07 (fixed in 3.3.07)
Published 2025-03-16. Last modified 2026-06-17.