Arbitrary Shortcode Execution in WordPress Download Manager Plugin
CVE-2024-11740
What is CVE-2024-11740?
CVE-2024-11740 describes a vulnerability within the Download Manager plugin for WordPress, where improper validation of values allows unauthenticated attackers to execute arbitrary shortcodes. This security flaw affects all versions of the plugin up to and including 3.3.03. Due to the lack of validation, an attacker can exploit this vulnerability to run malicious code, compromising the integrity of the affected WordPress site. Users are strongly advised to update to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Download Manager * <= 3.3.03
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved