CVE-2021-34639 HIGH

CVE-2021-34639: WordPress Download Manager <= 3.1.24 Authenticated Arbitrary File Upload

Vendor W3 Eden, Inc.
Product WordPress Download Manager
Weakness CWE-646
Published August 5, 2021
Last update August 4, 2024

CVSS base score

7.5/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions.

Explanation of Vulnerability in Simple Terms

02Summary

WordPress Download Manager version 3.1.24 contains a vulnerability that allows authenticated users with low privileges to read sensitive files, modify site content, or disrupt service. The vulnerability requires network access and specific conditions to exploit, but does not require user interaction. Site administrators should update immediately to a patched version.

What an attacker can do

03Attacker Capabilities

Read sensitive files, modify site content, or cause the site to become unavailable.

Potential impact on your site

04Site Impact

Authenticated attackers can access confidential data, alter posts/pages, or crash the site.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the site; network access required.

Key dates

06Disclosure timeline

August 5, 2021 CVE published
August 4, 2024 Record updated