The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php.
History

Thu, 12 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Wpbookingcalendar
Wpbookingcalendar secure Downloads
Weaknesses CWE-552
CPEs cpe:2.3:a:wpbookingcalendar:secure_downloads:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpbookingcalendar
Wpbookingcalendar secure Downloads

Sat, 17 May 2025 04:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php.
Title Secure Downloads < 1.2.3 - Admin+ Arbitrary File Download
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-05-17T03:24:49.534Z

Reserved: 2024-08-20T20:45:59.663Z

Link: CVE-2024-8031

cve-icon Vulnrichment

Updated: 2025-05-17T03:24:44.281Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:57.343

Modified: 2025-06-12T16:48:29.877

Link: CVE-2024-8031

cve-icon Redhat

No data.